CVE-2023-40519: Broadpeak Centralized Accounts Management Auth Agent
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00.19219575_ee9195b0, 01.01.01.30097902_fd999e76, and 00.12.01.9565588_1254b459 allows remote attackers to inject arbitrary web script or HTML via the disconnectMessage parameter.
Affected products
- Broadpeak Centralized Accounts Management Auth Agent: version 00.12.01.9565588_1254b459 only; version 01.01.00.19219575_ee9195b0 only; version 01.01.01.30097902_fd999e76 only
Published 2023-10-03. Last modified 2026-06-17.