CVE-2023-33732

MEDIUM

Microworld Technologies eScan mgmt console 14.0.1400.2281 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-33732. PoCs published by sahiloj.

AI-analyzed exploit summary This repository contains a writeup detailing a reflected XSS vulnerability in eScan Management Console 14.0.1400.2281. The vulnerability allows arbitrary code injection via the 'type', 'txtPolicyType', and 'Deletefileval' parameters.

Description

Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval.

Exploits (1)

nomisec WRITEUP 1 stars
by sahiloj · poc
https://github.com/sahiloj/CVE-2023-33732

This repository contains a writeup detailing a reflected XSS vulnerability in eScan Management Console 14.0.1400.2281. The vulnerability allows arbitrary code injection via the 'type', 'txtPolicyType', and 'Deletefileval' parameters.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: eScan Management Console 14.0.1400.2281
Auth required
Prerequisites: Valid user credentials for the eScan Management Console
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 6.1
EPSS 0.0084
EPSS Percentile 53.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
escanav/escan_management_console 14.0.1400.2281
Published May 31, 2023
Tracked Since Feb 18, 2026