CVE-2023-44826: XSS
Published Oct 10, 2023
·Updated
Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a crafted script.
Affected Software
1 affected component
EasyCorp ZenTao=18.6
Event History
Oct 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-44826?
The severity of CVE-2023-44826 is medium.
2
How does CVE-2023-44826 affect ZenTaoPMS v.18.6?
CVE-2023-44826 allows a local attacker to obtain sensitive information via a crafted script in ZenTaoPMS v.18.6.
3
How can an attacker exploit CVE-2023-44826?
An attacker can exploit CVE-2023-44826 by injecting a crafted script to obtain sensitive information.
4
Is there a fix available for CVE-2023-44826?
Yes, it is recommended to update ZenTaoPMS to a version that includes a fix for CVE-2023-44826.
5
What is CWE-79?
CWE-79 is a common weakness enumeration category for cross-site scripting vulnerabilities.