HomeAlgosecCVE-2023-46595

CVE-2023-46595

MEDIUM
5.9CVSS
Published: 2023-11-02
Updated: 2025-11-12
AI Analysis

Description

Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above)

CVSS Metrics

Vector
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L
Attack Vector
adjacent network
Complexity
high
Privileges
high
User Action
required
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
low
Weaknesses
CWE-79CWE-79

Metadata

Primary Vendor
ALGOSEC
Published
11/2/2023
Last Modified
11/12/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

algosec : fireflowalgosec : fireflowalgosec : fireflow

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2023-46595 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com