packetstormsecurity.com
http://packetstormsecurity.com/files/173038/Symantec-SiteMinder-WebAgent-12.52-Cross-Site-Scripting.html CVE-2023-23956
MEDIUM
Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)
Record summary
CVE-2023-23956 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Symantec SiteMinder WebAgent | CVE List | 12.5.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSymantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)ExploitDB exploitby Harshit JoshiNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-23956 packetstorm.newsexploit
https://packetstorm.news/files/id/173038 support.broadcom.com
https://support.broadcom.com/external/content/SecurityAdvisories/0/22221