NeoMind Fusion Platform Link cross site scripting
Published Aug 25, 2023
6.1
MEDIUMCVSS 3.1
EPSS 0.58%
Description
A vulnerability, which was classified as problematic, was found in NeoMind Fusion Platform up to 20230731. Affected is an unknown function of the file /fusion/portal/action/Link. The manipulation of the argument link leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-238026 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
Affected
- 20230731
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| NeoMind | Fusion Platform | unknown | Affected
|
- < 2023-07-31
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54389 Advisory
- https://l6x.notion.site/PoC-9f23bb9757374f82981de81604500d98?pvs=4 exploit
- https://vuldb.com/?ctiid.238026 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.238026 vdb-entrytechnical-descriptionPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54389 | Advisory | |
| https://l6x.notion.site/PoC-9f23bb9757374f82981de81604500d98?pvs=4 | exploit | |
| https://vuldb.com/?ctiid.238026 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.238026 | vdb-entrytechnical-descriptionPermissions Required |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data