CVE-2023-41266
Qlik Sense Path Traversal Vulnerability
⚠ KEVEPSS 82.6%
Description
Qlik Sense contains a path traversal vulnerability that allows a remote, unauthenticated attacker to create an anonymous session by sending maliciously crafted HTTP requests. This anonymous session could allow the attacker to send further requests to unauthorized endpoints.
How to fix CVE-2023-41266
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2023-41266 being exploited?
Yes — CVE-2023-41266 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.