Net-NTLM leak via stored HTML injection in FireFlow's VisualFlow workflow editor using Name and Description field. It also impacts
FireFlow's VisualFlow workflow editor
outbound actions using Name and Category parameter. Fixed in version A32.20 (b570 and above),
A32.50 (b400 and above),
A32.60 (b220 and above)
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-11-02 08:15
Updated : 2023-11-28 10:15
NVD link : CVE-2023-46595
Mitre link : CVE-2023-46595
JSON object : View
Products Affected
algosec
- fireflow
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
