Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44563 | Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser |
Fixes
Solution
Upgrade to SLM version 9.30.2
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC |
|
History
Thu, 03 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Snow
Published:
Updated: 2024-10-03T20:27:22.370Z
Reserved: 2023-07-25T13:29:16.203Z
Link: CVE-2023-3937
Updated: 2024-08-02T07:08:50.686Z
Status : Modified
Published: 2023-08-11T12:15:09.637
Modified: 2024-11-21T08:18:21.540
Link: CVE-2023-3937
No data.
OpenCVE Enrichment
No data.
EUVD