CVE-2023-49950

MEDIUM

Logpoint SIEM 6.10.0-7.x < 7.3.0 - Stored Cross-Site Scripting via Jinja Template in Alert View

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-49950. PoCs published by shrikeinfosec.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2023-49950, a stored XSS vulnerability in Logpoint SIEM. It explains the root cause, including insufficient sanitization in Jinja templating, weak CSP, and jQuery exploitation, along with proof-of-concept demonstrations.

Description

The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template in the Alert view. A remote attacker can craft a cross-site scripting (XSS) payload and send it to any system or device that sends logs to the SIEM. If an alert is created, the payload will execute upon the alert data being viewed with that template, which can lead to sensitive data disclosure.

Exploits (1)

nomisec WRITEUP
by shrikeinfosec · poc
https://github.com/shrikeinfosec/cve-2023-49950

This repository provides a detailed technical analysis of CVE-2023-49950, a stored XSS vulnerability in Logpoint SIEM. It explains the root cause, including insufficient sanitization in Jinja templating, weak CSP, and jQuery exploitation, along with proof-of-concept demonstrations.

Classification
Writeup 100%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Logpoint SIEM v6.1.0 to v7.2.4
No auth needed
Prerequisites: Access to a system that logs to Logpoint SIEM · Alert rule configured to display user-controlled input
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 5.4
EPSS 0.0050
EPSS Percentile 39.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
logpoint/siem 6.10.0 - 7.3.0
Published Feb 03, 2024
Tracked Since Feb 18, 2026