6.1
CVSSv3

CVE-2023-40519

Published: 03/10/2023 Updated: 05/10/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00.19219575_ee9195b0, 01.01.01.30097902_fd999e76, and 00.12.01.9565588_1254b459 allows remote malicious users to inject arbitrary web script or HTML via the disconnectMessage parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

broadpeak centralized accounts management auth agent 00.12.01.9565588_1254b459

broadpeak centralized accounts management auth agent 01.01.00.19219575_ee9195b0

broadpeak centralized accounts management auth agent 01.01.01.30097902_fd999e76