Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the URL directly.
References
Link | Resource |
---|---|
https://github.com/sahiloj/CVE-2023-33731/blob/main/CVE-2023-33731.md | Exploit Third Party Advisory |
https://owasp.org/www-community/attacks/xss/ | Not Applicable |
Configurations
History
No history.
Information
Published : 2023-06-02 12:15
Updated : 2023-06-09 16:49
NVD link : CVE-2023-33731
Mitre link : CVE-2023-33731
CVE.ORG link : CVE-2023-33731
JSON object : View
Products Affected
escanav
- escan_management_console
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')