Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the URL directly.
References
Link | Resource |
---|---|
https://github.com/sahiloj/CVE-2023-33731/blob/main/CVE-2023-33731.md | Exploit Third Party Advisory |
https://owasp.org/www-community/attacks/xss/ | Not Applicable |
Configurations
History
09 Jun 2023, 16:49
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:escanav:escan_management_console:14.0.1400.2281:*:*:*:*:*:*:* | |
References | (MISC) https://owasp.org/www-community/attacks/xss/ - Not Applicable | |
References | (MISC) https://github.com/sahiloj/CVE-2023-33731/blob/main/CVE-2023-33731.md - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
CWE | CWE-79 |
02 Jun 2023, 12:48
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-02 12:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-33731
Mitre link : CVE-2023-33731
CVE.ORG link : CVE-2023-33731
JSON object : View
Products Affected
escanav
- escan_management_console
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')