Security Advisory

CVE-2018-12903

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-06-26 22:00:00
Last updated 2024-08-05 08:45:02
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the VfManager.asmx SelectAccounts->DisplayName screen, a user's groups in ConfigurationPage, the Dialog Title field, and App Group Name in the Application Group Wizard.