CVE-2023-37636: XSS
A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37636?
CVE-2023-37636 is a stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1.
How does CVE-2023-37636 affect UVDesk Community Skeleton v1.1.1?
CVE-2023-37636 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.
What is the severity of CVE-2023-37636?
The severity of CVE-2023-37636 is medium with a CVSS score of 5.4.
How can I fix CVE-2023-37636?
To fix CVE-2023-37636, you should update UVDesk Community Skeleton to a version that includes the security patch.
Where can I find more information about CVE-2023-37636?
You can find more information about CVE-2023-37636 at the following reference: [CVE-2023-37636](https://www.esecforte.com/cve-2023-37636-stored-cross-site-scripting/)