CVE-2023-33731

Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the URL directly.
Configurations

Configuration 1 (hide)

cpe:2.3:a:escanav:escan_management_console:14.0.1400.2281:*:*:*:*:*:*:*

History

09 Jun 2023, 16:49

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:escanav:escan_management_console:14.0.1400.2281:*:*:*:*:*:*:*
References (MISC) https://github.com/sahiloj/CVE-2023-33731/blob/main/CVE-2023-33731.md - (MISC) https://github.com/sahiloj/CVE-2023-33731/blob/main/CVE-2023-33731.md - Exploit, Third Party Advisory
References (MISC) https://owasp.org/www-community/attacks/xss/ - (MISC) https://owasp.org/www-community/attacks/xss/ - Not Applicable
First Time Escanav escan Management Console
Escanav

02 Jun 2023, 12:48

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-02 12:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-33731

Mitre link : CVE-2023-33731

CVE.ORG link : CVE-2023-33731


JSON object : View

Products Affected

escanav

  • escan_management_console
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')