Vulnerability Description
Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Snowsoftware | Snow License Manager | >= 9.0.0, <= 9.30.1 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://community.snowsoftware.com/s/feed/0D56M00009gUexuSACIssue TrackingVendor Advisory
- https://community.snowsoftware.com/s/feed/0D56M00009gUexuSACIssue TrackingVendor Advisory
FAQ
What is CVE-2023-3937?
CVE-2023-3937 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger ...
How severe is CVE-2023-3937?
CVE-2023-3937 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3937?
Check the references section above for vendor advisories and patch information. Affected products include: Snowsoftware Snow License Manager, Microsoft Windows.