CVE-2023-4932

CVSS V2 None CVSS V3 None
Description
SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the `_program` parameter of the the `/SASStoredProcess/do` endpoint allows arbitrary JavaScript to be executed when specially crafted URL is opened by an authenticated user. The attack is possible from a low-privileged user. Only versions 9.4_M7 and 9.4_M8 were tested and confirmed to be vulnerable, status of others is unknown. For above mentioned versions hot fixes were published.
Overview
  • CVE ID
  • CVE-2023-4932
  • Assigner
  • CERT-PL
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-12-12T09:48:23.274Z
  • Last Modified Date
  • 2023-12-12T09:48:23.274Z
References
Reference URL Reference Tags
https://support.sas.com/kb/70/265.html vendor-advisory patch
https://cert.pl/en/posts/2023/12/CVE-2023-4932/ third-party-advisory
https://cert.pl/posts/2023/12/CVE-2023-4932/ third-party-advisory
History
Created Old Value New Value Data Type Notes
2024-06-24 19:33:04 Added to TrackCVE