CVE-2023-33736
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2023-33736 is a stored cross-site scripting (XSS) vulnerability affecting Dcat-Admin version 2.1.3-beta. This issue allows attackers to inject malicious web scripts or HTML code into a URL parameter, which is then stored and executed every time the page containing the vulnerable parameter is accessed. Attackers can exploit this vulnerability to steal user data, manipulate web applications, or launch further attacks against unsuspecting victims. Users are strongly advised to upgrade to a patched version of Dcat-Admin as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.