CVE-2023-46595

Net-NTLM leak via stored HTML injection in FireFlow's VisualFlow workflow editor using Name and Description field. It also impacts  FireFlow's VisualFlow workflow editor outbound actions using Name and Category parameter. Fixed in version A32.20 (b570 and above),  A32.50 (b400 and above),  A32.60 (b220 and above)
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:algosec:fireflow:a32.20:*:*:*:*:*:*:*
cpe:2.3:a:algosec:fireflow:a32.50:*:*:*:*:*:*:*

Information

Published : 2023-11-02 08:15

Updated : 2023-11-28 10:15


NVD link : CVE-2023-46595

Mitre link : CVE-2023-46595


JSON object : View

Products Affected

algosec

  • fireflow
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')