greenrocketsecurity.comVendor advisory
https://greenrocketsecurity.com/cve-2023-4951 CVE-2023-4951
LOW
Cross Site Scripting (XSS) Issue on "Client Based Authentication Policy Configuration" Screen
Record summary
CVE-2023-4951 has a selected CVSS score of 2.0 (low); EIP currently links 1 repository PoC.
Description
A cross site scripting issue was discovered with the pagination function on the "Client-based Authentication Policy Configuration" screen of the GreenRADIUS web admin interface. This issue is found in GreenRADIUS v5.1.1.1 and prior. A fix was included in v5.1.2.2.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GreenRADIUSBrowse Green Rocket Security / GreenRADIUSDefault status: unaffected | CVE List | Through 5.1.1.1 | affected |
Proofs of concept
1Repository PoCs
GitHubjaysharma786/CVE-2023-4951Repository PoCby jaysharma786Stars: 0Not analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-4951