Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-45992


A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.


Published

2023-10-19T19:15:16.223

Last Modified

2024-11-21T08:27:43.217

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.6 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-79
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application commscope ruckus_cloudpath_enrollment_system ≤ 5.12.5538 Yes

References