CVE-2023-23956

MEDIUM

Broadcom Symantec SiteMinder WebAgent - Cross-Site Scripting

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-23956. PoCs published by Harshit Joshi.

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Symantec SiteMinder WebAgent v12.52 via the SMAGENTNAME and TARGET parameters. The payload uses event handlers (onfocus) and autofocus to trigger arbitrary JavaScript execution.

Description

A user can supply malicious HTML and JavaScript code that will be executed in the client browser

Exploits (1)

exploitdb WORKING POC
by Harshit Joshi · textwebappshardware
https://www.exploit-db.com/exploits/51530

This exploit demonstrates a reflected XSS vulnerability in Symantec SiteMinder WebAgent v12.52 via the SMAGENTNAME and TARGET parameters. The payload uses event handlers (onfocus) and autofocus to trigger arbitrary JavaScript execution.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Symantec SiteMinder WebAgent v12.52
No auth needed
Prerequisites: Access to the vulnerable login page
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 5.4
EPSS 0.0297
EPSS Percentile 85.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
broadcom/symantec_siteminder_webagent 12.52
Published May 30, 2023
Tracked Since Feb 18, 2026