An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, will submit a cross-site scripting request to the Biller Direct system. This can result in the disclosure or modification of non-sensitive information.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2023-12-12T00:59:36.906Z

Updated: 2024-11-26T14:33:56.259Z

Reserved: 2023-09-11T07:15:13.775Z

Link: CVE-2023-42479

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-12T01:15:10.827

Modified: 2024-11-21T08:22:38.303

Link: CVE-2023-42479

cve-icon Redhat

No data.