First published: Fri Dec 08 2023(Updated: )
A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details.
Credit: bugreport@qualys.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualys Private Cloud Platform | <10.24.0.0 |
Customers should upgrade Qualys Private Cloud Platform to a minimum version of 10.24.0.0. For customer on Qualys Shared Cloud no actions are necessary.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6146 is classified as a stored XSS vulnerability that can potentially lead to unauthorized actions within the Qualys Private Cloud Platform.
To fix CVE-2023-6146, ensure that HTML encoding is implemented for user input in logging information presentation.
CVE-2023-6146 affects versions of the Qualys Private Cloud Platform prior to 10.24.0.0.
CVE-2023-6146 can enable attackers to execute arbitrary JavaScript in the context of users' browsers via stored XSS.
CVE-2023-6146 can be exploited by any user with login access to the Qualys Private Cloud Platform.