Description

Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to initiate an XSS attack by injecting malicious executable scripts into the application's code. Fixed in version A32.20 (b600 and above), A32.50 (b430 and above), A32.60 (b250 and above)

Published: 2024-02-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade ASMS suite to A32.20 (b600 and above), A32.50 (b430 and above), A32.60 (b250 and above) https://portal.algosec.com/en/downloads/hotfix_releases https://portal.algosec.com/en/downloads/hotfix_releases

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-50799 Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to initiate an XSS attack by injecting malicious executable scripts into the application's code. Fixed in version A32.20 (b600 and above), A32.50 (b430 and above), A32.60 (b250 and above)
History

Thu, 23 Jan 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Algosec
Algosec fireflow
CPEs cpe:2.3:a:algosec:fireflow:a32.20:*:*:*:*:*:*:*
cpe:2.3:a:algosec:fireflow:a32.50:*:*:*:*:*:*:*
cpe:2.3:a:algosec:fireflow:a32.60:*:*:*:*:*:*:*
Vendors & Products Algosec
Algosec fireflow

Subscriptions

Algosec Fireflow
cve-icon MITRE

Status: PUBLISHED

Assigner: AlgoSec

Published:

Updated: 2024-08-02T20:45:42.302Z

Reserved: 2023-10-23T10:00:57.893Z

Link: CVE-2023-46596

cve-icon Vulnrichment

Updated: 2024-05-23T19:01:13.039Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-15T06:15:45.453

Modified: 2025-01-23T17:43:12.833

Link: CVE-2023-46596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses