Vulnerability Details CVE-2023-6098
An XSS vulnerability has been discovered in ICS Business Manager affecting version 7.06.0028.7066. A remote attacker could send a specially crafted string exploiting the obdd_act parameter, allowing the attacker to steal an authenticated user's session, and perform actions within the application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.4%
CVSS Severity
CVSS v3 Score 6.3
Products affected by CVE-2023-6098
-
cpe:2.3:a:icssolution:ics_business_manager:7.06.0028.2802
-
cpe:2.3:a:icssolution:ics_business_manager:7.06.0028.7066
-
cpe:2.3:a:icssolution:ics_business_manager:7.06.0028.7089