CVE-2023-33732
MEDIUMMicroworld Technologies eScan mgmt console 14.0.1400.2281 - XSS
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-33732. PoCs published by sahiloj.
AI-analyzed exploit summary This repository contains a writeup detailing a reflected XSS vulnerability in eScan Management Console 14.0.1400.2281. The vulnerability allows arbitrary code injection via the 'type', 'txtPolicyType', and 'Deletefileval' parameters.
Description
Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval.
Exploits (1)
This repository contains a writeup detailing a reflected XSS vulnerability in eScan Management Console 14.0.1400.2281. The vulnerability allows arbitrary code injection via the 'type', 'txtPolicyType', and 'Deletefileval' parameters.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N