CVE-2023-49950

MEDIUM

Logpoint Siem < 7.3.0 - XSS

Title source: rule
STIX 2.1

Description

The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template in the Alert view. A remote attacker can craft a cross-site scripting (XSS) payload and send it to any system or device that sends logs to the SIEM. If an alert is created, the payload will execute upon the alert data being viewed with that template, which can lead to sensitive data disclosure.

Exploits (1)

nomisec WRITEUP
by shrikeinfosec · poc
https://github.com/shrikeinfosec/cve-2023-49950

Scores

CVSS v3 5.4
EPSS 0.0018
EPSS Percentile 39.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
logpoint/siem 6.10.0 - 7.3.0
Published Feb 03, 2024
Tracked Since Feb 18, 2026