CVE-2023-6365

In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within a device group.   If a WhatsUp Gold user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:*

History

19 Dec 2023, 16:52

Type Values Removed Values Added
CPE cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:*
Summary
  • (es) En las versiones de WhatsUp Gold lanzadas antes de la 2023.1, se identificó una vulnerabilidad de Cross-Site Scripting (XSS) almacenadas. Es posible que un atacante cree un payload XSS y almacene ese valor dentro de un grupo de dispositivos. Si un usuario de WhatsUp Gold interactúa con el payload manipulado, el atacante podría ejecutar JavaScript malicioso dentro del contexto del navegador de la víctima.
CVSS v2 : unknown
v3 : 7.6
v2 : unknown
v3 : 5.4
References () https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-December-2023 - () https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-December-2023 - Vendor Advisory
References () https://www.progress.com/network-monitoring - () https://www.progress.com/network-monitoring - Product
First Time Progress
Progress whatsup Gold

14 Dec 2023, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-14 16:15

Updated : 2023-12-19 16:52


NVD link : CVE-2023-6365

Mitre link : CVE-2023-6365

CVE.ORG link : CVE-2023-6365


JSON object : View

Products Affected

progress

  • whatsup_gold
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')