{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2023-3937", "ASSIGNER": "security@snowsoftware.com", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser" } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", "cweId": "CWE-79" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Snow Software", "product": { "product_data": [ { "product_name": "Snow License Manager", "version": { "version_data": [ { "version_affected": "<=", "version_name": "9.0.0", "version_value": "9.30.1" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC", "refsource": "MISC", "name": "https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC" } ] }, "generator": { "engine": "Vulnogram 0.1.0-dev" }, "source": { "discovery": "EXTERNAL" }, "solution": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Upgrade to SLM version 9.30.2" } ], "value": "Upgrade to SLM version 9.30.2" } ], "credits": [ { "lang": "en", "value": "Can Do\u011fu & Himanshu Giri" } ], "impact": { "cvss": [ { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 4.8, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "HIGH", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N", "version": "3.1" } ] } }