Vulnerability Description
A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation, has been discovered. This vulnerability allows for Stored XSS attacks to occur. Multiple areas within the administration interface of the webserver lack adequate input validation, resulting in multiple instances of Stored XSS vulnerabilities.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kiloview | P1 Firmware | - |
| Kiloview | P1 | - |
| Kiloview | P2 Firmware | - |
| Kiloview | P2 | - |
Related Weaknesses (CWE)
References
- https://advisories.ncsc.nl/advisory?id=NCSC-2024-0273Third Party Advisory
- https://advisories.ncsc.nl/advisory?id=NCSC-2024-0273Third Party Advisory
FAQ
What is CVE-2023-41922?
CVE-2023-41922 is a vulnerability with a CVSS score of 7.2 (HIGH). A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation, has been discovered. This vulnerability allows for Stored XSS attacks to occur....
How severe is CVE-2023-41922?
CVE-2023-41922 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-41922?
Check the references section above for vendor advisories and patch information. Affected products include: Kiloview P1 Firmware, Kiloview P1, Kiloview P2 Firmware, Kiloview P2.