CVE-2023-23208
MEDIUMCVSS 6.1/10EPSS 0.31%
Last modified
CVE-2023-23208 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Genesys | Administrator Extension | < 9.0.105.15 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-23208?
Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Structure page of the iWD plugin, aka GAX-11261.
How severe is CVE-2023-23208?
CVE-2023-23208 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 0.31% probability of exploitation in the next 30 days.
How do I fix CVE-2023-23208?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-2317DOM-based XSS in updater/update.html in Typora before 1.6.7 …9.6
- CVE-2023-2318DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in M…9.6
- CVE-2023-2319It was discovered that an update for PCS package in RHBA-202…9.8
- CVE-2023-23192IS Decisions UserLock MFA 11.01 is vulnerable to authenticat…7.2
- CVE-2023-2320The CF7 Google Sheets Connector WordPress plugin before 5.0.…6.1
- CVE-2023-23205An issue was discovered in lib60870 v2.3.2. There is a memor…5.5
- CVE-2023-2321The WPForms Google Sheet Connector WordPress plugin before 3…6.1
- CVE-2023-2322Cross-site Scripting (XSS) - Stored in GitHub repository pim…5.4
- CVE-2023-2323Cross-site Scripting (XSS) - Stored in GitHub repository pim…5.4
- CVE-2023-2324The Elementor Forms Google Sheet Connector WordPress plugin …6.1
- CVE-2023-2325Stored XSS Vulnerability in M-Files Classic Web versions bef…5.4
- CVE-2023-2326The Gravity Forms Google Sheet Connector WordPress plugin be…6.5
Are you affected by CVE-2023-23208?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
