VYPR
Medium severity4.3NVD Advisory· Published Sep 1, 2023· Updated Jun 17, 2026

CVE-2023-4710

CVE-2023-4710

Description

A vulnerability classified as problematic was found in TOTVS RM 12.1. Affected by this vulnerability is an unknown functionality of the component Portal. The manipulation of the argument d leads to cross site scripting. The attack can be launched remotely. The identifier VDB-238573 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

3
  • Totara/Rm2 versions
    cpe:2.3:a:totvs:rm:12.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:totvs:rm:12.1:*:*:*:*:*:*:*
    • (no CPE)range: 12.1
  • Totara/RM Portalllm-create

Patches

Vulnerability mechanics

References

2
  • vuldb.comnvdPermissions RequiredThird Party AdvisoryVDB Entry
  • vuldb.comnvdThird Party AdvisoryVDB Entry

News mentions

0

No linked articles in our index yet.