Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-42479
HistoryDec 12, 2023 - 1:15 a.m.

Cross site scripting

2023-12-1201:15:00
PRIOn knowledge base
www.prio-n.com
2
cross site scripting
unauthenticated attacker
hidden url
frame
biller direct system
disclosure
modification

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.7%

An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, will submit a cross-site scripting request to the Biller Direct system. This can result in the disclosure or modification of non-sensitive information.

CPENameOperatorVersion
biller_directeq750
biller_directeq635

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.7%

Related for PRION:CVE-2023-42479