VYPR
Medium severity6.1NVD Advisory· Published Jun 22, 2023· Updated Jun 17, 2026

CVE-2023-33387

CVE-2023-33387

Description

A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allows attackers to steal targeted users' login data by sending a crafted link.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:*:*:*:*:*:*:*:*range: >=15.1.0,<16.1.1
    • cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:16.1.1:-:*:*:*:*:*:*
    • cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:16.1.1:p1:*:*:*:*:*:*
    • cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:16.1.1:p2:*:*:*:*:*:*
    • cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:16.1.1:p3:*:*:*:*:*:*
    • cpe:2.3:a:datev:eg_personal-management_system_comfort\/comfort_plus:16.1.1:p4:*:*:*:*:*:*
  • DATEV eG/Personal-Management System Comfort/Comfort Plusdescription
  • Range: 15.1.0 - 16.1.1 P4

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.