CVE-2018-12903: XSS
In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the VfManager.asmx SelectAccounts->DisplayName screen, a user's groups in ConfigurationPage, the Dialog Title field, and App Group Name in the Application Group Wizard.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-12903?
CVE-2018-12903 is a vulnerability in CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603 that allows for persistent cross-site scripting (XSS) attacks.
How severe is CVE-2018-12903?
CVE-2018-12903 has a severity rating of medium, with a CVSS score of 5.4.
How does CVE-2018-12903 occur?
CVE-2018-12903 occurs due to persistent XSS via an account name on the create token screen, the VfManager.asmx SelectAccounts->DisplayName screen, a user's groups in ConfigurationPage, the Dialog Title field, and App Group Name in the Application.
How can CVE-2018-12903 be exploited?
CVE-2018-12903 can be exploited by inserting malicious code into the vulnerable fields mentioned in the previous question, allowing an attacker to execute arbitrary scripts in a victim's browser.
Is there a fix for CVE-2018-12903?
Yes, a patch or update to CyberArk Endpoint Privilege Manager should be applied to fix CVE-2018-12903.