CVE-2023-45062
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2023-45062 is a newly discovered cross-site scripting (XSS) vulnerability affecting versions 2.4.6 and below of the Thomas Scholl canvasio3D Light plugin. This issue allows an attacker to inject malicious scripts into a website, which can then be reflected back to unsuspecting users, potentially resulting in data theft or unauthorized actions. The vulnerability stems from insufficient input validation in the plugin, making it an unauthenticated risk for users who visit affected websites. It is essential for users to update their plugin to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.