MEDIUM
Multiple vulnerabilities in Canopsis of Capensis
Published Oct 3, 2023
4.8
MEDIUMCVSS 3.1
EPSS 0.48%
Description
This vulnerability could allow an attacker to store a malicious JavaScript payload in the login footer and login page description parameters within the administration panel.
Affected products
-
- Version 23.04-alpha3StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Canopsis version 23.10.0 includes fixes for the reported vulnerability, and was released on 31 October 2023.
Weaknesses (1)
References (3)
- https://git.canopsis.net/canopsis/canopsis-community/-/blob/develop/community/sources/webcore/src/canopsis-next/src/config.js?ref_type=heads#L38
- https://git.canopsis.net/canopsis/canopsis-community/-/blob/develop/community/sources/webcore/src/canopsis-next/src/helpers/html.js?ref_type=heads
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-canopsis-capensis Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Oct 3, 2023
Updated Oct 1, 2024
Reserved Jun 12, 2023
Link CVE-2023-3196
CISA Vulnrichment
Updated Sep 5, 2024