Description
Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above)
No analysis available yet.
Remediation
Vendor Solution
Upgrade ASMS suite to A32.20 (b570 or above), A32.50 (b390 or above) https://portal.algosec.com/en/downloads/hotfix_releases https://portal.algosec.com/en/downloads/hotfix_releases
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-50798 | Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above) |
References
| Link | Providers |
|---|---|
| https://cwe.mitre.org/data/definitions/79.html |
|
History
Wed, 12 Nov 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above) | Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above) |
Status: PUBLISHED
Assigner: AlgoSec
Published:
Updated: 2025-11-12T08:38:33.676Z
Reserved: 2023-10-23T10:00:57.893Z
Link: CVE-2023-46595
No data.
Status : Modified
Published: 2023-11-02T08:15:08.040
Modified: 2025-11-12T09:15:40.030
Link: CVE-2023-46595
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD