Persistent XSS Vulnerability in CyberArk Endpoint Privilege Manager
CVE-2018-12903

5.4MEDIUM

Key Information:

Vendor

Cyberark

Vendor
CVE Published:
26 June 2018

What is CVE-2018-12903?

In CyberArk Endpoint Privilege Manager version 10.2.1.603, a persistent XSS vulnerability is present that allows attackers to inject malicious scripts through various input fields such as account names on the create token screen, the DisplayName on the VfManager.asmx SelectAccounts screen, user groups in the ConfigurationPage, and other fields like Dialog Title and App Group Name in the Application Group Wizard. Exploiting this vulnerability can lead to unauthorized access and manipulation of user sessions, making it imperative for organizations to address this issue.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-12903 : Persistent XSS Vulnerability in CyberArk Endpoint Privilege Manager