PatchSiren

Yordam CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Yordam CVE published 2023-09-14

CVE-2023-4676

CVE-2023-4676 is a reflected cross-site scripting (XSS) issue in Yordam MedasPro. The public record ties the flaw to input that is not properly neutralized during web page generation, which can allow attacker-controlled content to be reflected back into a user’s browser. NVD lists the affected MedasPro range as versions before 28.