medium

Super FabriXss

Published Tue, Mar 14th, 2023
Platforms

Summary

Azure Service Fabric Explorer (SFX) was affected by an XSS vulnerability that could have allowed a malicious script to be reflected off a web application. After a potential victim clicked on a crafted malicious URL, the attacker could remotely toggle the ‘Cluster’ Event Type setting under the Events tab. This could lead to unauthenticated remote code execution on a container hosted on a Service Fabric node.

Affected Services

Azure Service Fabric Explorer (SFX)

Remediation

None required

Tracked CVEs

CVE-2023-23383

References

Entry Status
Finalized
Disclosure Date
Tue, Dec 20th, 2022
Exploitablity Period
-
Known ITW Exploitation
-
Detection Methods
-
Piercing Index Rating
-
Discovered by
Lidor Ben Shitrit, Orca Security