CVE-2011-0459

EUVD-2011-0479
Cross-site scripting (XSS) vulnerability in Cyber-Ark Password Vault Web Access (PVWA) 5.0 and earlier, 5.5 through 5.5 patch 4, and 6.0 through 6.0 patch 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
Affected Products (NVD)
VendorProductVersion
cyber-arkpassword_vault_web_access
𝑥
≤ 5.0
cyber-arkpassword_vault_web_access
4.0
cyber-arkpassword_vault_web_access
5.5
cyber-arkpassword_vault_web_access
5.5:patch4
cyber-arkpassword_vault_web_access
6.0
cyber-arkpassword_vault_web_access
6.0:patch2
𝑥
= Vulnerable software versions