CVE-2023-43763: XSS
Published Sep 22, 2023
·Updated
Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint. This affects WithSecure Policy Manager 15 on Windows and Linux.
Affected Software
2 affected components
WithSecure F-secure Policy Manager Linux Kernel=15.00
WithSecure F-secure Policy Manager Windows=15.00
Event History
Sep 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-43763?
CVE-2023-43763 is a vulnerability that allows XSS (Cross-Site Scripting) attacks via an unvalidated parameter in the endpoint.
2
Which products are affected by CVE-2023-43763?
CVE-2023-43763 affects WithSecure Policy Manager 15 on both Windows and Linux operating systems.
3
How severe is CVE-2023-43763?
CVE-2023-43763 has a severity rating of medium, with a severity value of 6.1.
4
What is the Common Weakness Enumeration (CWE) for CVE-2023-43763?
The CWE for CVE-2023-43763 is CWE-79 (Improper Neutralization of Input During Web Page Generation).
5
How can I mitigate CVE-2023-43763?
To mitigate CVE-2023-43763, apply the necessary patches and updates provided by WithSecure to address the unvalidated parameter in the endpoint.