VYPR
Medium severity6.3NVD Advisory· Published Nov 13, 2023· Updated Jun 17, 2026

CVE-2023-6098

CVE-2023-6098

Description

An XSS vulnerability has been discovered in ICS Business Manager affecting version 7.06.0028.7066. A remote attacker could send a specially crafted string exploiting the obdd_act parameter, allowing the attacker to steal an authenticated user's session, and perform actions within the application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:icssolution:ics_business_manager:7.06.0028.2802:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:icssolution:ics_business_manager:7.06.0028.2802:*:*:*:*:*:*:*
    • cpe:2.3:a:icssolution:ics_business_manager:7.06.0028.7066:*:*:*:*:*:*:*
    • cpe:2.3:a:icssolution:ics_business_manager:7.06.0028.7089:*:*:*:*:*:*:*
    • (no CPE)range: 7.06.0028.7066
  • Range: = 7.06.0028.7066

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.