CVE Published: 14/09/2023 |
CVE Updated: 25/09/2024 |
CVE Year: 2023 Source: GreenRocketSecurity |
Vendor: Green Rocket Security |
Product: GreenRADIUS Status : PUBLISHED
CVE-2023-4951 Description
A cross site scripting issue was discovered with the pagination function on the "Client-based Authentication Policy Configuration" screen of the GreenRADIUS web admin interface. This issue is found in GreenRADIUS v5.1.1.1 and prior. A fix was included in v5.1.2.2.
Metrics
CVSS Version: 3.1 |
Base Score: 2 LOW Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* LOW Privileges Required (PR)* HIGH User Interaction (UI)* REQUIRED Scope (S)* UNCHANGED