CVE-2023-49950
MEDIUMLogpoint SIEM 6.10.0-7.x < 7.3.0 - Stored Cross-Site Scripting via Jinja Template in Alert View
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-49950. PoCs published by shrikeinfosec.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2023-49950, a stored XSS vulnerability in Logpoint SIEM. It explains the root cause, including insufficient sanitization in Jinja templating, weak CSP, and jQuery exploitation, along with proof-of-concept demonstrations.
Description
The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template in the Alert view. A remote attacker can craft a cross-site scripting (XSS) payload and send it to any system or device that sends logs to the SIEM. If an alert is created, the payload will execute upon the alert data being viewed with that template, which can lead to sensitive data disclosure.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2023-49950, a stored XSS vulnerability in Logpoint SIEM. It explains the root cause, including insufficient sanitization in Jinja templating, weak CSP, and jQuery exploitation, along with proof-of-concept demonstrations.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N