Security
Loading…

CVE-2023-41265

CRITICALCVSS 9.6Known Exploited
Description

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

Timeline
Published:August 29th, 2023 11:15 PM
Last modified:August 5th, 2026 5:16 AM
Added to KEV:December 7th, 2023
CVSS Scoring

CVSS v3: 9.6 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Affected Software
From NVD CPE configuration data

Vendors

qlik

Products

qlik_sense
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute