CVE-2023-NNN
Multiple Reflected cross-site scripting (XSS)
More information
Multiple Reflected cross-site scripting (XSS) vulnerabilities exists in the F-Secure Policy Manager due to an unvalidated parameter in the endpoint a remote attacker can provide a malicious input to trigger a XSS vulnerability.
This issue was reported to WithSecure through the Vulnerability Reward Program. No known exploit or attack has been seen in the wild.
NOTE: We have applied for, but not yet received a CVE identifier for this Advisory. We will update the advisory page once we have obtained the CVE number.
Contributors
WithSecure would like to thank following person for bringing this issue to our attention.