An XSS vulnerability has been discovered in ICS Business Manager affecting version 7.06.0028.7066. A remote attacker could send a specially crafted string exploiting the obdd_act parameter, allowing the attacker to steal an authenticated user's session, and perform actions within the application.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2023-11-13T13:13:26.543Z

Updated: 2024-08-30T19:22:47.444Z

Reserved: 2023-11-13T09:53:09.886Z

Link: CVE-2023-6098

cve-icon Vulnrichment

Updated: 2024-08-02T08:21:17.144Z

cve-icon NVD

Status : Modified

Published: 2023-11-13T13:15:08.237

Modified: 2024-11-21T08:43:07.903

Link: CVE-2023-6098

cve-icon Redhat

No data.