Symantec Management Console fails to properly validate/sanitize certain external input, allowing the potential for reflected cross-site scripting attempts. These attempts may come from authorized, but non-privileged network users or, in some instances, from unauthorized external individuals who are able to entice an actively logged-in management console user to click on a maliciously-crafted HTML link. Successful targeting of these issues could result in an authorized Symantec Management Console user’s management session with associated privileges being hijacked.