CVE-2023-6146: Stored XSS Vulnerability in QualysGuard VM/PC
A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6146?
CVE-2023-6146 is classified as a stored XSS vulnerability that can potentially lead to unauthorized actions within the Qualys Private Cloud Platform.
How do I fix CVE-2023-6146?
To fix CVE-2023-6146, ensure that HTML encoding is implemented for user input in logging information presentation.
Which versions of the Qualys Private Cloud Platform are affected by CVE-2023-6146?
CVE-2023-6146 affects versions of the Qualys Private Cloud Platform prior to 10.24.0.0.
What type of attacks can CVE-2023-6146 enable?
CVE-2023-6146 can enable attackers to execute arbitrary JavaScript in the context of users' browsers via stored XSS.
Can CVE-2023-6146 be exploited by any user?
CVE-2023-6146 can be exploited by any user with login access to the Qualys Private Cloud Platform.