CVE-2023-26100

In Progress Flowmon before 12.2.0, an application endpoint failed to sanitize user-supplied input. A threat actor could leverage a reflected XSS vulnerability to execute arbitrary code within the context of a Flowmon user's web browser.
Configurations

Configuration 1 (hide)

cpe:2.3:o:progress:flowmon_os:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:50

Type Values Removed Values Added
References () https://support.kemptechnologies.com/hc/en-us/articles/12736934205837 - Third Party Advisory () https://support.kemptechnologies.com/hc/en-us/articles/12736934205837 - Third Party Advisory
References () https://www.flowmon.com/en - Product () https://www.flowmon.com/en - Product

Information

Published : 2023-04-21 12:15

Updated : 2024-11-21 07:50


NVD link : CVE-2023-26100

Mitre link : CVE-2023-26100

CVE.ORG link : CVE-2023-26100


JSON object : View

Products Affected

progress

  • flowmon_os
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')