Vulnerabilities (CVE)

Filtered by vendor Algosec Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-46595 1 Algosec 1 Fireflow 2023-11-28 N/A 6.1 MEDIUM
Net-NTLM leak via stored HTML injection in FireFlow's VisualFlow workflow editor using Name and Description field. It also impacts  FireFlow's VisualFlow workflow editor outbound actions using Name and Category parameter. Fixed in version A32.20 (b570 and above),  A32.50 (b400 and above),  A32.60 (b220 and above)
CVE-2013-5092 1 Algosec 1 Firewall Analyzer 2017-08-29 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CVE-2014-4164 1 Algosec 1 Fireflow 2015-12-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in AlgoSec FireFlow 6.3-b230 allows remote attackers to inject arbitrary web script or HTML via a user signature to SelfService/Prefs.html.
CVE-2013-7318 1 Algosec 1 Firewall Analyzer 2014-08-06 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in BusinessFlow/login in AlgoSec Firewall Analyzer 6.4 allows remote attackers to inject arbitrary web script or HTML via the message parameter.