HTTP: OpenCATS Questionnaire.php doActions Stored Cross-Site Scripting

This signature detects attempts to exploit a known cross-site scripting vulnerability against OpenCATS Questionnaire.php doActions. It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.

Extended Description

Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used to steal other users cookies and force users to make actions without their knowledge.

Affected Products

Opencats opencats

References

CVE: CVE-2023-27293

Short Name
HTTP:XSS:OPENCATS-DACTN
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2023-27293 Cross-Site OpenCATS Questionnaire.php Scripting Stored doActions
Release Date
04/06/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3587
False Positive
Unknown
Vendors

Opencats

Found a potential security threat?