CVE-2023-33515

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jun 14, 2023
Updated: Jan 6, 2025
CWE ID 79

Summary

CVE-2023-33515 identifies a Cross-Site Scripting (XSS) vulnerability in SoftExpert Excellence Suite 2.1.9. Attackers can exploit this weakness by injecting malicious scripts into query screens, causing unintended execution in users' web browsers. Consequences of an XSS attack include session hijacking, data theft, and the spread of malware. To mitigate this risk, users should update their software to the latest version and employ input validation techniques to block potentially harmful code. This vulnerability poses a significant risk to organizations and individuals using the affected software.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share