Persistent XSS Vulnerability in CyberArk Endpoint Privilege Manager
CVE-2018-12903
5.4MEDIUM
What is CVE-2018-12903?
In CyberArk Endpoint Privilege Manager version 10.2.1.603, a persistent XSS vulnerability is present that allows attackers to inject malicious scripts through various input fields such as account names on the create token screen, the DisplayName on the VfManager.asmx SelectAccounts screen, user groups in the ConfigurationPage, and other fields like Dialog Title and App Group Name in the Application Group Wizard. Exploiting this vulnerability can lead to unauthorized access and manipulation of user sessions, making it imperative for organizations to address this issue.