Vulnerability Description
Cross Site Scripting (XSS) vulnerability in GBCOM LAC WEB Control Center version lac-1.3.x, allows attackers to create an arbitrary device.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gbcom | Lac Web Control Center | lac-1.3.x |
Related Weaknesses (CWE)
References
- https://github.com/shellpei/GBCOM-XSS/blob/main/CVE-2023-29707Third Party Advisory
- https://holistic-height-e6d.notion.site/GBCOM-LAC-WEB-Control-Center-cross-site-ExploitThird Party Advisory
- https://github.com/shellpei/GBCOM-XSS/blob/main/CVE-2023-29707Third Party Advisory
- https://holistic-height-e6d.notion.site/GBCOM-LAC-WEB-Control-Center-cross-site-ExploitThird Party Advisory
FAQ
What is CVE-2023-29707?
CVE-2023-29707 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Cross Site Scripting (XSS) vulnerability in GBCOM LAC WEB Control Center version lac-1.3.x, allows attackers to create an arbitrary device.
How severe is CVE-2023-29707?
CVE-2023-29707 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-29707?
Check the references section above for vendor advisories and patch information. Affected products include: Gbcom Lac Web Control Center.