CVE-2023-33761
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2023-33761: eMedia Consulting's simpleRedak software, versions up to 2.47.23.05, has been identified with a reflected cross-site scripting (XSS) vulnerability. An attacker can exploit this issue by injecting malicious code through the /view/cb/format_642.php component, potentially gaining unauthorized access to user sessions or data. The vulnerability poses a significant risk, particularly in organizational environments, as it can be triggered through specially crafted URLs or links. To mitigate this threat, it is recommended that users upgrade to the latest version of simpleRedak as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.