VulnerabilityModified
CVE-2023-33731
Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the URL directly.
MEDIUM 6.1EPSS 0.81%
Does this matter?
Lower severity and a low EPSS score (0.81%). Track it; it rarely justifies an emergency change on its own.
Description
Reflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the URL directly.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- escanav/escan management console
- Source
- cve@mitre.org
References
- https://github.com/sahiloj/CVE-2023-33731/blob/main/CVE-2023-33731.mdExploit, Third Party Advisory
- https://owasp.org/www-community/attacks/xss/Not Applicable
- https://github.com/sahiloj/CVE-2023-33731/blob/main/CVE-2023-33731.mdExploit, Third Party Advisory
- https://owasp.org/www-community/attacks/xss/Not Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.