CVE-2023-0125

A vulnerability was found in Control iD Gerencia Web 1.30. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation of the argument Nome leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-217717 was assigned to this vulnerability.
References
Link Resource
https://vuldb.com/?ctiid.217717 Permissions Required Third Party Advisory
https://vuldb.com/?id.217717 Third Party Advisory
https://www.notion.so/ControlID-XSS-7ab891644a794103b582a59360f071a5 Permissions Required Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:control_id_panel_project:control_id_panel:-:*:*:*:*:*:*:*

History

14 May 2024, 11:57

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en Control iD Gerencia Web 1.30. Ha sido declarada problemática. Una función desconocida del componente Web Interface es afectada por esta vulnerabilidad. La manipulación del argumento Nome conduce a cross-site scripting. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-217717.

19 Sep 2023, 06:15

Type Values Removed Values Added
Summary A vulnerability was found in Control iD Panel. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation of the argument Nome leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-217717 was assigned to this vulnerability. A vulnerability was found in Control iD Gerencia Web 1.30. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation of the argument Nome leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-217717 was assigned to this vulnerability.

Information

Published : 2023-01-09 21:15

Updated : 2024-05-17 02:17


NVD link : CVE-2023-0125

Mitre link : CVE-2023-0125

CVE.ORG link : CVE-2023-0125


JSON object : View

Products Affected

control_id_panel_project

  • control_id_panel
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')