Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-3937


Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser


Published

2023-08-11T12:15:09.637

Last Modified

2024-11-21T08:18:21.540

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application snowsoftware snow_license_manager ≤ 9.30.1 Yes
Operating System microsoft windows - No

References