Back

MEDIUM

Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission

Published Feb 28, 2023

Description

Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used to steal other users’ cookies and force users to make actions without their knowledge.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner tenable
Published Feb 28, 2023
Updated Mar 21, 2025
Reserved Feb 27, 2023
CISA Vulnrichment
Updated Mar 21, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner tenable
Published Feb 28, 2023
Updated Mar 21, 2025
Exploited since n/a
EUVD-2023-31071