CVE-2023-45281: XSS
Published Oct 19, 2023
·Updated
An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.
Affected Software
1 affected component
Spaceapplications Yamcs=5.8.6
Event History
Oct 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
05:15 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for the Yamcs vulnerability?
The vulnerability ID for the Yamcs vulnerability is CVE-2023-45281.
2
What is the severity of the Yamcs vulnerability?
The severity of the Yamcs vulnerability is medium (6.1).
3
How can attackers exploit the Yamcs vulnerability?
Attackers can exploit the Yamcs vulnerability by uploading a crafted HTML file to obtain the session cookie.
4
Which version of Yamcs is affected by this vulnerability?
Yamcs version 5.8.6 is affected by this vulnerability.
5
Is there a fix available for the Yamcs vulnerability?
No specific fix information is provided.