CVE-2023-46948
MEDIUMTemenos T24 Browser R19.40 - Reflected Cross-Site Scripting via Skin Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-46948. PoCs published by AzraelsBlade.
AI-analyzed exploit summary The repository provides a detailed technical writeup for CVE-2023-46948, a reflected XSS vulnerability in Temenos T24 R19.40, affecting the 'skin' parameter in specific JSP files. It includes request/response examples and remediation details but lacks functional exploit code.
Description
A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the skin parameter in the about.jsp and genrequest.jsp components.
Exploits (1)
The repository provides a detailed technical writeup for CVE-2023-46948, a reflected XSS vulnerability in Temenos T24 R19.40, affecting the 'skin' parameter in specific JSP files. It includes request/response examples and remediation details but lacks functional exploit code.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N