← Back

CVE-2023-34203

nvd nist
Published: Jun 23, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through 12.6.x before 12.7.

Affected (5)

3 products
Openedge
Openedge Explorer
Openedge Management
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Progress
Before 11.7.16
From 12.0 to 12.2.12
From 12.3 to 12.7
Before 12.7
Before 12.7

References (2)

Source: cve@mitre.org
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.