CVE-2023-23956
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.1epss 3.1%
from disclosure to weapon20 days
Published on NVDMay 30
1st PoC+20d
exploitation probability
3.1%top 14% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
n/a · Symantec SiteMinder WebAgentpublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/51530unverifiedcve_referencepacketstormsecurity.com/files/173038/Symantec-SiteMinder-WebAgent-12.52-Cross-Site-Scripting.htmlunverifiedcve_referencepacketstorm.news/files/id/173038unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.