Lucene search

K
cveINCIBECVE-2023-4100
HistoryOct 03, 2023 - 12:15 p.m.

CVE-2023-4100

2023-10-0312:15:10
CWE-79
INCIBE
web.nvd.nist.gov
14
cve-2023-4100
xss
dos
nvd
vulnerability

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:H

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

21.8%

Allows an attacker to perform XSS attacks stored on certain resources. Exploiting this vulnerability can lead to a DoS condition, among other actions.

Affected configurations

Nvd
Vulners
Node
qsigeqsigeMatch3.0.0.0
VendorProductVersionCPE
qsigeqsige3.0.0.0cpe:2.3:a:qsige:qsige:3.0.0.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "QSige",
    "vendor": "IDM Sistemas QSige",
    "versions": [
      {
        "status": "affected",
        "version": "3.0.0.0"
      }
    ]
  }
]

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:H

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

21.8%

Related for CVE-2023-4100