VYPR

Fireflow

by Manageengine

CVEs (4)

  • CVE-2022-36783MedOct 25, 2022
    risk 0.42cvss 6.5epss 0.00

    AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter called IntersectudRule on the search/result.html page. The malicious user changes the request from POST to GET and sends the URL to another user (victim).…

  • CVE-2023-46595MedNov 2, 2023
    risk 0.38cvss 5.9epss 0.00

    Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above)

  • CVE-2023-46596MedFeb 15, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to initiate an XSS attack by injecting malicious executable scripts into the application's code.…

  • CVE-2014-4164Jun 16, 2014
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in AlgoSec FireFlow 6.3-b230 allows remote attackers to inject arbitrary web script or HTML via a user signature to SelfService/Prefs.html.