CVE-2023-31434 Information

Description

The parameters nutzer_titel nutzer_vn and nutzer_nn in the user profile and langID and ONLINEID in direct links in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 do not validate input which allows authenticated attackers to inject HTML Code and XSS payloads in multiple locations.

Reference

https://cves.at/posts/cve-2023-31434/writeup/

Share on: