CVE-2023-33761

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jun 2, 2023
Updated: Jan 8, 2025
CWE ID 79

Summary

CVE-2023-33761: eMedia Consulting's simpleRedak software, versions up to 2.47.23.05, has been identified with a reflected cross-site scripting (XSS) vulnerability. An attacker can exploit this issue by injecting malicious code through the /view/cb/format_642.php component, potentially gaining unauthorized access to user sessions or data. The vulnerability poses a significant risk, particularly in organizational environments, as it can be triggered through specially crafted URLs or links. To mitigate this threat, it is recommended that users upgrade to the latest version of simpleRedak as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share