CVE-2023-3829
CVSS 3.1 Score 8.4 of 10 (high)
Details
Published Jul 22, 2023
Updated: May 17, 2024
CWE ID 284
Summary
CVE-2023-3829 is a newly disclosed cross-site scripting vulnerability affecting the Support Ticket Handler component of Bug Finder ICOGenie 1.0. The issue lies within the /user/ticket/create file, and an attacker can manipulate the argument message to inject malicious code. This attack can be initiated remotely, making it a significant security risk. Unfortunately, the vendor was not responsive to early disclosures about this vulnerability, and no patch or mitigation has been provided as of yet. (VDB-235150)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share