8.8

CVE-2023-4296

​If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the target device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IntlandCodebeamer Version21.09.0 Update-
IntlandCodebeamer Version21.09.0 Updatesp1
IntlandCodebeamer Version21.09.0 Updatesp10
IntlandCodebeamer Version21.09.0 Updatesp11
IntlandCodebeamer Version21.09.0 Updatesp12
IntlandCodebeamer Version21.09.0 Updatesp13
IntlandCodebeamer Version21.09.0 Updatesp2
IntlandCodebeamer Version21.09.0 Updatesp3
IntlandCodebeamer Version21.09.0 Updatesp4
IntlandCodebeamer Version21.09.0 Updatesp5
IntlandCodebeamer Version21.09.0 Updatesp6
IntlandCodebeamer Version21.09.0 Updatesp7
IntlandCodebeamer Version21.09.0 Updatesp8
IntlandCodebeamer Version21.09.0 Updatesp9
IntlandCodebeamer Version22.04.0 Update-
IntlandCodebeamer Version22.04.0 Updatesp1
IntlandCodebeamer Version22.04.0 Updatesp2
IntlandCodebeamer Version22.04.0 Updatesp3
IntlandCodebeamer Version22.04.0 Updatesp4
IntlandCodebeamer Version22.04.0 Updatesp5
IntlandCodebeamer Version22.10.0 Update-
IntlandCodebeamer Version22.10.0 Updatesp1
IntlandCodebeamer Version22.10.0 Updatesp2
IntlandCodebeamer Version22.10.0 Updatesp3
IntlandCodebeamer Version22.10.0 Updatesp4
IntlandCodebeamer Version22.10.0 Updatesp5
IntlandCodebeamer Version22.10.0 Updatesp6
IntlandCodebeamer Version22.10.0 Updatesp7
IntlandCodebeamer Version22.10.0 Updatesp8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.05% 0.768
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
ics-cert@hq.dhs.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.