#VU101633 Cross-site scripting in IBM Sterling File Gateway - CVE-2023-52292
Published: December 11, 2024
IBM Sterling File Gateway
IBM Corporation
Description
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.