CVE-2023-6146: Qualys Private Cloud Platform

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details. 

Affected products

  • Qualys Private Cloud Platform: before 10.24.0.0 (fixed in 10.24.0.0)

Published 2023-12-08. Last modified 2026-06-17.