CVE-2023-49260
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2023-49260 is a new Cross-Site Scripting (XSS) vulnerability that allows an attacker to modify the Message of the Day (MOTD) banner and redirect victims to the "terminal_tool.cgi" path. This XSS vulnerability can be exploited in conjunction with CVE-2023-49255 to launch more effective attacks. An attacker can inject malicious scripts into the MOTD banner, which is then displayed to the victim in their web terminal session. Successful exploitation of this vulnerability could lead to unauthorized access or data theft from the affected system. It is crucial for organizations to apply the necessary patches as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.