CVE-2023-46595

Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editorallows an attackerto obtain victims domain credentials and Net-NTLM hash which can leadto relay domain attacks. Fixed inA32.20 (b570 or above),  A32.50 (b390 or above)

Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
ADJACENT_NETWORK
HIGH
HIGH
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L
AlgoSecCNA
5.9 MEDIUM
ADJACENT_NETWORK
HIGH
HIGH
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L
CVEADP
---
---