CVE Published: 29/09/2023 |
CVE Updated: 23/09/2024 |
CVE Year: 2023 Source: tibco |
Vendor: TIBCO Software Inc. |
Product: TIBCO Nimbus Status : PUBLISHED
CVE-2023-26218 Description
The Web Client component of TIBCO Software Inc.\'s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim\'s local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.\'s TIBCO Nimbus: versions 10.6.0 and below.
Metrics
CVSS Version: 3.1 |
Base Score: 8 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H