CVE-2023-46596
CVSS V2 None
CVSS V3 None
Description
Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to initiate an XSS attack by injecting malicious executable scripts into the application's code. Fixed in version A32.20 (b600 and above), A32.50 (b430 and above), A32.60 (b250 and above)
Overview
- CVE ID
- CVE-2023-46596
- Assigner
- AlgoSec
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-02-15T06:07:19.393Z
- Last Modified Date
- 2024-06-04T17:22:16.471Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://www.algosec.com/docs/en/cves/Content/tech-notes/cves/cve-2023-46596.htm |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-46596 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46596 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 22:49:21 | Added to TrackCVE |