CVE-2023-37826 Vulnerability Description A cross-site scripting (XSS) vulnerability in General Solutions Steiner GmbH CASE 3 Taskmanagement V 3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fieldname parameter. Vulnerability Type Cross Site Scripting (XSS) Vendor of Product General Solutions Steiner GmbH Affected Product Code Base CASE 3 Taskmanagement - V 3.3 Affected Component Feldname Attack Type Remote Impact Code Execution true Attack Vectors An attacker can exploit this vulnerability by injecting arbitrary and potentially malicious JavaScript code into the fieldname parameter. Reference https://case.contwise.com/php/portal_case.php Discoverer Leon von Sturm zu Vehlingen