CVE-2023-38350: XSS
Published Jul 15, 2023
·Updated
PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.
Affected Software
1 affected component
PNP4Nagios PNP4Nagios=0.6.26
Event History
Jul 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-38350?
CVE-2023-38350 is classified as a stored XSS vulnerability, which poses a serious security risk.
2
How do I fix CVE-2023-38350?
To fix CVE-2023-38350, it is recommended to update PNP4Nagios to the latest version that addresses the vulnerability.
3
What software does CVE-2023-38350 affect?
CVE-2023-38350 affects PNP4Nagios version 0.6.26.
4
What type of vulnerability is CVE-2023-38350?
CVE-2023-38350 is a stored cross-site scripting (XSS) vulnerability in the AJAX controller via the basket API.
5
Can CVE-2023-38350 allow unauthorized access?
Yes, CVE-2023-38350 can potentially allow attackers to execute malicious scripts in the context of the user’s session.