CVE-2023-6364

HIGH

WhatsUp Gold < 23.1.0 - Stored Cross-Site Scripting in Dashboard Component

Title source: llm
STIX 2.1

Description

In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified.  It is possible for an attacker to craft a XSS payload and store that value within a dashboard component.   If a WhatsUp Gold user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser.

References (2)

Core 2

Scores

CVSS v3 7.6
EPSS 0.0001
EPSS Percentile 2.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-79
Status published
Products (1)
progress/whatsup_gold < 23.1.0
Published Dec 14, 2023
Tracked Since Feb 18, 2026