Medium severity6.3NVD Advisory· Published Nov 13, 2023· Updated Jun 17, 2026
CVE-2023-6098
CVE-2023-6098
Description
An XSS vulnerability has been discovered in ICS Business Manager affecting version 7.06.0028.7066. A remote attacker could send a specially crafted string exploiting the obdd_act parameter, allowing the attacker to steal an authenticated user's session, and perform actions within the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:icssolution:ics_business_manager:7.06.0028.2802:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:icssolution:ics_business_manager:7.06.0028.2802:*:*:*:*:*:*:*
- cpe:2.3:a:icssolution:ics_business_manager:7.06.0028.7066:*:*:*:*:*:*:*
- cpe:2.3:a:icssolution:ics_business_manager:7.06.0028.7089:*:*:*:*:*:*:*
- (no CPE)range: 7.06.0028.7066
- Range: = 7.06.0028.7066
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.