First published: Sun Sep 17 2023(Updated: )
A vulnerability classified as problematic has been found in Tongda OA 11.10. Affected is an unknown function of the file /general/ipanel/menu_code.php?MENU_TYPE=FAV. The manipulation of the argument OA_SUB_WINDOW leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239868.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tongda2000 Tongda Oa | =11.10 | |
=11.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5026 is medium with a score of 6.1.
CVE-2023-5026 affects an unknown function of the file /general/ipanel/menu_code.php?MENU_TYPE=FAV in Tongda OA 11.10, leading to cross-site scripting (XSS) vulnerabilities.
Yes, CVE-2023-5026 can be exploited remotely.
CVE-2023-5026 belongs to the CWE category 79 - Cross-Site Scripting (XSS).
To fix CVE-2023-5026, it is recommended to apply the latest security patches or updates provided by Tongda2000 for Tongda OA 11.10.