CVE-2023-4592 is a Cross-Site Scripting (XSS) vulnerability found in WPN-XM Serverstack version 0.8.6. A remote attacker can exploit this by injecting a specially crafted JavaScript payload into the /tools/webinterface/index.php parameter. This allows for the retrieval of an authenticated user's cookie session details, leading to session hijacking. Rated as MEDIUM severity with a CVSS score of 6.1, the attack requires user interaction (UI:R) but can be executed over the network (AV:N). The potential impact includes compromise of confidentiality and integrity (C:L/I:L). Currently, there is no evidence of active exploitation (KEV: No), nor are there public exploit modules available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, indicating low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8.6CPE matchmatch criteria | cpe:2.3:a:wpn-xm:wpn-xm:0.8.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.