CVE-2023-32193

A vulnerability has been identified in which unauthenticated cross-site 
scripting (XSS) in Norman's public API endpoint can be exploited. This 
can lead to an attacker exploiting the vulnerability to trigger 
JavaScript code and execute commands remotely.
Basic XSS
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
suseCNA
8.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
CISA-ADPADP
---
---