CVE-2023-20868

Severity
6.1MEDIUM
EPSS
0.2%
top 58.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26

Description

NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5nsx-tNSX-T 3.2.x VCF 4.5.x

🔴Vulnerability Details

2
CVEList
CVE-2023-20868: NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation2023-05-26
GHSA
GHSA-cxmv-pg69-r77p: NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation2023-05-26

📋Vendor Advisories

1
VMware
NSX-T update addresses cross-site scripting vulnerability (CVE-2023-20868)2023-05-23
CVE-2023-20868 (MEDIUM CVSS 6.1) | NSX-T contains a reflected cross-si | cvebase.io