HTTP: OpenCATS Questionnaire.php doActions Stored Cross-Site Scripting
This signature detects attempts to exploit a known cross-site scripting vulnerability against OpenCATS Questionnaire.php doActions. It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.
Extended Description
Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used to steal other users cookies and force users to make actions without their knowledge.
Affected Products
Opencats opencats
References
CVE: CVE-2023-27293
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Opencats