CVE-2023-49574 HIGH

CVE-2023-49574: XSS vulnerability in VX Search Enterprise

Vendor Flexense
Product VX Search Enterprise
Weakness CWE-79 · XSS
Published May 24, 2024
Last update August 2, 2024

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

A vulnerability has been discovered in VX Search Enterprise affecting version 10.2.14 that could allow an attacker to execute persistent XSS through /add_job in job_name. This vulnerability could allow an attacker to store malicious JavaScript payloads on the system to be triggered when the page loads.

Key dates

02Disclosure timeline

May 24, 2024 CVE published
August 2, 2024 Record updated

Related vulnerabilities

04Related CVE