Medium severity6.1NVD Advisory· Published Jun 22, 2023· Updated Jun 17, 2026
CVE-2023-33387
CVE-2023-33387
Description
A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allows attackers to steal targeted users' login data by sending a crafted link.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:*:*:*:*:*:*:*:*range: >=15.1.0,<16.1.1
- cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:16.1.1:-:*:*:*:*:*:*
- cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:16.1.1:p1:*:*:*:*:*:*
- cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:16.1.1:p2:*:*:*:*:*:*
- cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:16.1.1:p3:*:*:*:*:*:*
- cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:16.1.1:p4:*:*:*:*:*:*
- DATEV eG/Personal-Management System Comfort/Comfort Plusdescription
- Range: 15.1.0 - 16.1.1 P4
Patches
Vulnerability mechanics
References
3- apps.datev.de/help-center/documents/1021479nvdVendor Advisory
- support.veda.net/datev.phpnvdThird Party Advisory
- www.tuv.com/landingpage/de/schwachstelle/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.