CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-45992

Critical · CVSS 9.6

RUCKUS Cloudpath — Persistent Cross-Site Scripting (Stored XSS) and Cross-Site Request Forgery (CSRF) leading to admin privilege escalation

CVSS
9.6
nvd
EPSS
KEV
No
Class
other
CWE-79, CWE-352

Description

A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.

Search profile — drives PoC discovery

Symbols server.cloudpath/admin/enrollmentData/enrollmentDataCloudpathadmin management interface
Keywords CVE-2023-45992RUCKUS Cloudpath XSS CSRFCloudpath stored XSSCloudpath admin privilege escalationCloudpath enrollmentDataCloudpath 5.12 build 5538Ruckus Cloudpath PoCharry935 CVE-2023-45992
Versions: <= 5.12 build 5538

Ranked PoCs (2) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z