
Cloud Vulnerability DB
A community-led vulnerabilities database
An XSS (Cross-Site Scripting) vulnerability has been discovered in Repox version 2.3.7 and earlier. The vulnerability was disclosed on December 12, 2023, and was assigned identifier CVE-2023-6719. This security flaw affects the web application's user interaction handling mechanism (INCIBE Advisory).
The vulnerability has been assigned a CVSS v3.1 base score of 6.1 MEDIUM (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) by NIST NVD, while INCIBE assigned it a score of 6.3 MEDIUM (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L). The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). The issue allows an attacker to send specially crafted JavaScript payloads to users (NIST NVD).
When successfully exploited, this vulnerability allows an attacker to compromise interactions between a user and the vulnerable application. The attacker can gain full control of the user's session by successfully executing the malicious JavaScript payload (INCIBE Advisory).
As of the vulnerability disclosure, no official fix or mitigation has been reported for this vulnerability (INCIBE Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."