CVE-2023-4709 is a problematic cross-site scripting (XSS) vulnerability found in TOTVS RM 12.1, specifically within the Login.aspx file's Portal component, affecting an unknown function when manipulating the VIEWSTATE argument. While remotely exploitable, the attack complexity and exploitability are rated as high and difficult, respectively, with a CVSS score of 6.1 (Medium) and a potential impact of low confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, and the vendor states the vulnerability is mitigated in standard configurations where VIEWSTATE is disabled by default.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1CPE matchmatch criteria | cpe:2.3:a:totvs:rm:12.1:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.