CVE-2023-3726: OCSInventory-ocsreports 2.12.0 - Stored cross-site Scripting
Published Jan 4, 2024
·Updated
OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting.
Affected Software
1 affected component
Ocsinventory-ng Ocsinventory-ocsreports=2.12.0
Event History
Jan 4, 2024
CVE Published
02:39 PM
Data Sourced
02:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-3726?
CVE-2023-3726 has a medium severity, indicating a moderate risk of exploitation.
2
How do I fix CVE-2023-3726?
To fix CVE-2023-3726, update OCSInventory-ocsreports to version 2.12.1 or later to eliminate the stored XSS vulnerability.
3
What systems are affected by CVE-2023-3726?
CVE-2023-3726 specifically affects OCSInventory-ocsreports version 2.12.0.
4
What type of vulnerability is CVE-2023-3726?
CVE-2023-3726 is a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
5
What impact does CVE-2023-3726 have on users?
CVE-2023-3726 can potentially allow attackers to steal user data and perform actions on behalf of authenticated users.