CVE-2023-4296

If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the target device.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
icscertCNA
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
intlandcodebeamer
21.09.0
intlandcodebeamer
21.09.0:sp1
intlandcodebeamer
21.09.0:sp10
intlandcodebeamer
21.09.0:sp11
intlandcodebeamer
21.09.0:sp12
intlandcodebeamer
21.09.0:sp13
intlandcodebeamer
21.09.0:sp2
intlandcodebeamer
21.09.0:sp3
intlandcodebeamer
21.09.0:sp4
intlandcodebeamer
21.09.0:sp5
intlandcodebeamer
21.09.0:sp6
intlandcodebeamer
21.09.0:sp7
intlandcodebeamer
21.09.0:sp8
intlandcodebeamer
21.09.0:sp9
intlandcodebeamer
22.04.0
intlandcodebeamer
22.04.0:sp1
intlandcodebeamer
22.04.0:sp2
intlandcodebeamer
22.04.0:sp3
intlandcodebeamer
22.04.0:sp4
intlandcodebeamer
22.04.0:sp5
intlandcodebeamer
22.10.0
intlandcodebeamer
22.10.0:sp1
intlandcodebeamer
22.10.0:sp2
intlandcodebeamer
22.10.0:sp3
intlandcodebeamer
22.10.0:sp4
intlandcodebeamer
22.10.0:sp5
intlandcodebeamer
22.10.0:sp6
intlandcodebeamer
22.10.0:sp7
intlandcodebeamer
22.10.0:sp8
𝑥
= Vulnerable software versions