2024-04-03 18:03:25 +00:00
{
"id" : "CVE-2023-44040" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2024-04-03T17:15:47.273" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T08:25:10.190" ,
2024-04-03 18:03:25 +00:00
"vulnStatus" : "Awaiting Analysis" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-04-03 18:03:25 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate."
2024-04-07 02:03:21 +00:00
} ,
{
"lang" : "es" ,
"value" : "En VeridiumID anterior a 3.5.0, la p\u00e1gina del proveedor de identidad es susceptible a una vulnerabilidad de Cross Site Scripting (XSS) que puede ser explotada por un atacante interno no autenticado para la ejecuci\u00f3n de JavaScript en el contexto del usuario que intenta autenticarse."
2024-04-03 18:03:25 +00:00
}
] ,
2024-11-05 17:03:22 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 6.1 ,
"baseSeverity" : "MEDIUM" ,
2024-11-05 17:03:22 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2024-11-05 17:03:22 +00:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 2.7
}
]
} ,
"weaknesses" : [
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-79"
}
]
}
] ,
2024-04-03 18:03:25 +00:00
"references" : [
{
"url" : "https://docs.veridiumid.com/docs/v3.5/security-advisory#id-%28v3.52%29SecurityAdvisory-Acknowledgement" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://veridiumid.com/veridium-id-authentication-platform/" ,
"source" : "cve@mitre.org"
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://docs.veridiumid.com/docs/v3.5/security-advisory#id-%28v3.52%29SecurityAdvisory-Acknowledgement" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://veridiumid.com/veridium-id-authentication-platform/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2024-04-03 18:03:25 +00:00
}
]
}