mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-26 13:37:50 +02:00
876 B
876 B
CVE-2018-12903
Description
In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the VfManager.asmx SelectAccounts->DisplayName screen, a user's groups in ConfigurationPage, the Dialog Title field, and App Group Name in the Application Group Wizard.
POC
Reference
- http://code610.blogspot.com/2018/06/exploiting-cyberark-1021603.html
- http://code610.blogspot.com/2018/06/exploiting-cyberark-1021603.html
Github
No PoCs found on GitHub currently.