CVE-2023-46596 - CERT CVE
ID CVE-2023-46596
Sažetak Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to initiate an XSS attack by injecting malicious executable scripts into the application's code. Fixed in version A32.20 (b600 and above), A32.50 (b430 and above), A32.60 (b250 and above)
Reference
CVSS
Base: 5.1
Impact: 4.7
Exploitability:0.4
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH LOW LOW
CVSS vektor CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L
Zadnje važnije ažuriranje 23-01-2025 - 17:43
Objavljeno 15-02-2024 - 06:15