Medium severity5.4NVD Advisory· Published Jun 26, 2018· Updated Jun 17, 2026
CVE-2018-12903
CVE-2018-12903
Description
In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the VfManager.asmx SelectAccounts->DisplayName screen, a user's groups in ConfigurationPage, the Dialog Title field, and App Group Name in the Application Group Wizard.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: =10.2.1.603
Patches
Vulnerability mechanics
References
1- code610.blogspot.com/2018/06/exploiting-cyberark-1021603.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.