CVE-2023-34830
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2023-34830 is a newly discovered cross-site scripting (XSS) vulnerability affecting version 24 of the i-doit Open open-source IT documentation software. The issue lies in the login page's handling of the timeout parameter, which can be exploited through a reflected attack. Successful exploitation could allow an attacker to inject malicious scripts into a user's browser session, potentially leading to data theft or unauthorized actions. Users are strongly advised to apply the latest patch or upgrade to a non-vulnerable version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- I-doit
Affected Vendors
- Idoit