CVE-2023-23956

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published May 30, 2023
Updated: Jan 14, 2025
CWE ID 79

Summary

CVE-2023-23956 is a new vulnerability that grants attackers the ability to inject malicious HTML and JavaScript code into a web application. This allows the attacker to execute unwanted scripts in the user's browser, potentially leading to information disclosure, session hijacking, or other forms of unauthorized access. The vulnerability can be exploited by tricking a user into visiting a specially crafted webpage or by embedding the malicious code into an advertisement or other content that is displayed on the affected site. Organizations are advised to patch affected systems as soon as possible to mitigate the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share