Persistent XSS Vulnerability in CyberArk Endpoint Privilege Manager
CVE-2018-12903
Key Information:
- Vendor
Cyberark
- Vendor
- CVE Published:
- 26 June 2018
Badges
What is CVE-2018-12903?
In CyberArk Endpoint Privilege Manager version 10.2.1.603, a persistent XSS vulnerability is present that allows attackers to inject malicious scripts through various input fields such as account names on the create token screen, the DisplayName on the VfManager.asmx SelectAccounts screen, user groups in the ConfigurationPage, and other fields like Dialog Title and App Group Name in the Application Group Wizard. Exploiting this vulnerability can lead to unauthorized access and manipulation of user sessions, making it imperative for organizations to address this issue.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
