First published: Tue Oct 10 2023(Updated: )
Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a crafted script.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EasyCorp ZenTao | =18.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-44826 is medium.
CVE-2023-44826 allows a local attacker to obtain sensitive information via a crafted script in ZenTaoPMS v.18.6.
An attacker can exploit CVE-2023-44826 by injecting a crafted script to obtain sensitive information.
Yes, it is recommended to update ZenTaoPMS to a version that includes a fix for CVE-2023-44826.
CWE-79 is a common weakness enumeration category for cross-site scripting vulnerabilities.