CVE-2023-4196: Cross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
Published Aug 6, 2023
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
Affected Software
2 affected componentsFixes available
composer/cockpit-hq/cockpit<2.6.3
2.6.3
Agentejo Cockpit<2.6.3
Remediation
Event History
Aug 6, 2023
CVE Published
via MITRE·05:32 PM
Data Sourced
via MITRE·05:32 PM
DescriptionSeverityWeakness
Data Sourced
06:15 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
06:30 PM
Frequently Asked Questions
1
What is CVE-2023-4196?
CVE-2023-4196 is a vulnerability that allows for Cross-site Scripting (XSS) attacks in the GitHub repository cockpit-hq/cockpit prior to version 2.6.3.
2
How severe is CVE-2023-4196?
CVE-2023-4196 has a severity rating of 8.3, which is considered high.
3
How can the CVE-2023-4196 vulnerability be exploited?
The CVE-2023-4196 vulnerability can be exploited by uploading an HTML file to execute malicious code on a targeted website.
4
What software is affected by CVE-2023-4196?
The GitHub repository cockpit-hq/cockpit prior to version 2.6.3 is affected by CVE-2023-4196.
5
How can CVE-2023-4196 be remediated?
To fix CVE-2023-4196, you should update the affected software to version 2.6.3 or higher.