← Back

CVE-2023-28350

nvd nist
Published: May 31, 2023Modified: Jan 13, 2025

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console applications, enabling an attacker to execute JavaScript in these applications. Due to the rich and highly privileged functionality offered by the Teacher Console, the ability to silently exploit Cross Site Scripting (XSS) on the Teacher Machine enables remote code execution on any connected student machine (and the teacher's machine).

Affected (1)

Products: Faronics: Insight
1 product
Insight
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 10.0.19045
Running on/withPlatform Versions
Microsoft
Windows
All versions

Timeline

No history available yet.