CVE-2023-41343: Ragic No-Code Database Builder - Stored XSS
Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-41343?
CVE-2023-41343 is a vulnerability found in Ragic No-Code Database Builder that allows for Stored Cross-Site Scripting (XSS) attacks.
What is the severity of CVE-2023-41343?
CVE-2023-41343 has a severity rating of medium with a CVSS score of 5.4.
How does CVE-2023-41343 work?
CVE-2023-41343 occurs due to insufficient filtering of special characters in the file uploading function, allowing an attacker to inject JavaScript code and perform Stored Cross-Site Scripting (XSS) attacks.
Which software is affected by CVE-2023-41343?
Ragic Enterprise Cloud Database is affected by CVE-2023-41343.
How can I mitigate CVE-2023-41343?
To mitigate CVE-2023-41343, it is recommended to apply the latest security patches or updates provided by Ragic to fix the insufficient filtering of special characters in the file uploading function.