Vulnerability Description
A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualys | Private Cloud Platform | < 10.24.0.0 |
Related Weaknesses (CWE)
References
- https://www.qualys.com/security-advisories/Vendor Advisory
- https://www.qualys.com/security-advisories/Vendor Advisory
FAQ
What is CVE-2023-6146?
CVE-2023-6146 is a vulnerability with a CVSS score of 5.7 (MEDIUM). A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a use...
How severe is CVE-2023-6146?
CVE-2023-6146 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6146?
Check the references section above for vendor advisories and patch information. Affected products include: Qualys Private Cloud Platform.