CVE-2023-49950

The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template in the Alert view. A remote attacker can craft a cross-site scripting (XSS) payload and send it to any system or device that sends logs to the SIEM. If an alert is created, the payload will execute upon the alert data being viewed with that template, which can lead to sensitive data disclosure.
Configurations

Configuration 1 (hide)

cpe:2.3:a:logpoint:siem:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:34

Type Values Removed Values Added
References () https://github.com/shrikeinfosec/cve-2023-49950/blob/main/cve-2023-49950.md - Exploit () https://github.com/shrikeinfosec/cve-2023-49950/blob/main/cve-2023-49950.md - Exploit
References () https://servicedesk.logpoint.com/hc/en-us/articles/14124495377437-Stored-XSS-Vulnerability-in-Alerts-via-Log-Injection - Vendor Advisory () https://servicedesk.logpoint.com/hc/en-us/articles/14124495377437-Stored-XSS-Vulnerability-in-Alerts-via-Log-Injection - Vendor Advisory

13 Feb 2024, 00:42

Type Values Removed Values Added
CPE cpe:2.3:a:logpoint:siem:*:*:*:*:*:*:*:*
References () https://github.com/shrikeinfosec/cve-2023-49950/blob/main/cve-2023-49950.md - () https://github.com/shrikeinfosec/cve-2023-49950/blob/main/cve-2023-49950.md - Exploit
References () https://servicedesk.logpoint.com/hc/en-us/articles/14124495377437-Stored-XSS-Vulnerability-in-Alerts-via-Log-Injection - () https://servicedesk.logpoint.com/hc/en-us/articles/14124495377437-Stored-XSS-Vulnerability-in-Alerts-via-Log-Injection - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Logpoint siem
Logpoint
CWE CWE-79

03 Feb 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-03 09:15

Updated : 2024-11-21 08:34


NVD link : CVE-2023-49950

Mitre link : CVE-2023-49950

CVE.ORG link : CVE-2023-49950


JSON object : View

Products Affected

logpoint

  • siem
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')