CVE-2023-23949
26.01.2023, 21:18
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
Vendor | Product | Version |
---|---|---|
broadcom | symantec_identity_governance_and_administration | 14.3 |
broadcom | symantec_identity_governance_and_administration | 14.4.1 |
broadcom | symantec_identity_governance_and_administration | 14.4.2 |
broadcom | symantec_identity_manager | 14.3 |
broadcom | symantec_identity_manager | 14.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
- CWE-779 - Logging of Excessive DataThe software logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.