CVE-2017-6322

medium

Description

Symantec Management Console fails to properly validate/sanitize certain external input, allowing the potential for reflected cross-site scripting attempts. These attempts may come from authorized, but non-privileged network users or, in some instances, from unauthorized external individuals who are able to entice an actively logged-in management console user to click on a maliciously-crafted HTML link. Successful targeting of these issues could result in an authorized Symantec Management Console user’s management session with associated privileges being hijacked.

Details

Source: Mitre, NVD

Published: 2017-08-03

Risk Information

CVSS v2

Base Score: 3.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium