vendor:
SiteMinder WebAgent
by:
Harshit Joshi
5.4
CVSS
MEDIUM
Cross-site scripting (XSS)
79
CWE
Product Name: SiteMinder WebAgent
Affected Version From: 12.52
Affected Version To: 12.52
Patch Exists: NO
Related CWE: CVE-2023-23956
CPE: a:symantec:siteminder_webagent:12.52
Platforms Tested: Linux, Windows
2023
Symantec SiteMinder WebAgent v12.52 – Cross-site scripting (XSS)
I am writing to report two XSS vulnerabilities (CVE-2023-23956) that I have discovered in the Symantec SiteMinder WebAgent. The vulnerability is related to the improper handling of user input and has been assigned the Common Weakness Enumeration (CWE) code CWE-79. The CVSSv3 score for this vulnerability is 5.4.