CVE-2023-26429

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jun 20, 2023
Updated: Jan 12, 2024
CWE ID 77

Summary

CVE-2023-26429 is a vulnerability where control characters in user feedback content were not properly removed during exportation. This issue allowed attackers to inject unexpected content, potentially disrupting the data structure. To mitigate this risk, we now eliminate all control characters except for whitespace characters during the export process. No publicly available exploits for this vulnerability have been reported.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share