CVE-2023-5026
Published on: Not Yet Published
Last Modified on: 09/20/2023 03:43:00 PM UTC
Certain versions of Tongda Oa from Tongda2000 contain the following vulnerability:
A vulnerability classified as problematic has been found in Tongda OA 11.10. Affected is an unknown function of the file /general/ipanel/menu_code.php?MENU_TYPE=FAV. The manipulation of the argument OA_SUB_WINDOW leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239868.
- CVE-2023-5026 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Tongda - OA version = 11.10
CVSS3 Score: 6.1 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
CVE-2023-5026: Tongda OA cross site scripting | vuldb.com text/html |
![]() |
No Description Provided | github.com text/html |
![]() |
Login required | vuldb.com text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Tongda2000 | Tongda Oa | 11.10 | All | All | All |
- cpe:2.3:a:tongda2000:tongda_oa:11.10:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE