Threat intelligence report · CISA KEV

CVE-2023-41266: Qlik Sense Path Traversal Vulnerability

Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

· high severity · unattributed attribution

Evidence and provenance

Original source
CISA KEV report ↗
Published
2023-12-07T00:00:00Z
Confidence basis
No actor match
Record ID
da04bdb248a6f48a1d8c

Vulnerabilities

CVE-2023-41266

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.