leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.7.1-231128, 1.8.0-231127 and 1.8.1-231127 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-246104.", "datePublished": "2023-11-24T15:00:06Z", "dateModified": "2025-06-03T14:09:44Z", "keywords": "CVE-2023-6275, vulnerability, CVE, security, Fluig Platform, TOTVS", "about": { "@type": "SoftwareApplication", "name": "Fluig Platform", "applicationCategory": "SecurityApplication", "operatingSystem": "All" } }
CVE-2023-6275 LOW

CVE-2023-6275: TOTVS Fluig Platform mobileredir openApp.jsp cross site scripting

Vendor Totvs
Product Fluig Platform
Weakness CWE-79 · XSS
Published November 24, 2023
Last update June 3, 2025

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

A vulnerability was found in TOTVS Fluig Platform 1.6.x/1.7.x/1.8.0/1.8.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /mobileredir/openApp.jsp of the component mobileredir. The manipulation of the argument redirectUrl/user with the input "><script>alert(document.domain)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.7.1-231128, 1.8.0-231127 and 1.8.1-231127 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-246104.

Key dates

02Disclosure timeline

November 24, 2023 CVE published
June 3, 2025 Record updated

Related vulnerabilities

04Related CVE