CVE-2023-3937

Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:snowsoftware:snow_license_manager:*:*:*:*:service_provider:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:18

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de cross site scripting en el portal web del Snow Software License Manager desde la versión 9.0.0 hasta la 9.30.1 inclusive en Windows permite a un usuario autenticado con privilegios elevados desencadenar un ataque de cross site scripting a través del navegador web.
References () https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC - Issue Tracking, Vendor Advisory () https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC - Issue Tracking, Vendor Advisory

18 Aug 2023, 14:30

Type Values Removed Values Added
First Time Microsoft
Snowsoftware snow License Manager
Snowsoftware
Microsoft windows
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
References (MISC) https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC - (MISC) https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC - Issue Tracking, Vendor Advisory
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:snowsoftware:snow_license_manager:*:*:*:*:service_provider:*:*:*
CWE CWE-79

11 Aug 2023, 12:58

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-11 12:15

Updated : 2024-11-21 08:18


NVD link : CVE-2023-3937

Mitre link : CVE-2023-3937

CVE.ORG link : CVE-2023-3937


JSON object : View

Products Affected

snowsoftware

  • snow_license_manager

microsoft

  • windows
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')