Back

MEDIUM

Improper Neutralization of Input During Web Page Generation in WPN-XM Serverstack

Published Nov 3, 2023

Description

A Cross-Site Scripting vulnerability has been detected in WPN-XM Serverstack affecting version 0.8.6. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload through the /tools/webinterface/index.php parameter and retrieve the cookie session details of an authenticated user, resulting in a session hijacking.

Affected products

Remediation

Vendor solution

There is no reported solution at this time.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Nov 3, 2023
Updated Sep 5, 2024
Reserved Aug 29, 2023
CISA Vulnrichment
Updated Sep 5, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner INCIBE
Published Nov 3, 2023
Updated Sep 5, 2024
Exploited since n/a
EUVD-2023-54445