CVE-2023-6098: Icssolution Ics Business Manager

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

An XSS vulnerability has been discovered in ICS Business Manager affecting version 7.06.0028.7066. A remote attacker could send a specially crafted string exploiting the obdd_act parameter, allowing the attacker to steal an authenticated user's session, and perform actions within the application.

Affected products

  • Icssolution Ics Business Manager: version 7.06.0028.2802 only; version 7.06.0028.7066 only; version 7.06.0028.7089 only

Published 2023-11-13. Last modified 2026-06-17.