CVE-2023-46596

Published Feb 15, 2024

Last updated 9 months ago

Overview

Description
Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to initiate an XSS attack by injecting malicious executable scripts into the application's code. Fixed in version A32.20 (b600 and above), A32.50 (b430 and above), A32.60 (b250 and above)
Source
security.vulnerabilities@algosec.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.1
Impact score
4.7
Exploitability score
0.4
Vector string
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L
Severity
MEDIUM

Weaknesses

security.vulnerabilities@algosec.com
CWE-79

Social media

Hype score
Not currently trending