Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HEscanav Escan Management Console
APPEscanav14.0.1400.2281
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
Related vulnerabilities
CVE-2024-42919CRITICAL9.8PL ✓same product
Błąd kontroli dostępu w eScan Management Console (acteScanAVReport)
CVE-2023-33730CRITICAL9.8PL ✓same product
Privilege Escalation w eScan Management Console — hasła w plain text
CVE-2023-31702HIGH7.2same product
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote att...
CVE-2023-34835MEDIUM5.4same product
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allo...
CVE-2023-34836MEDIUM5.4same product
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allo...