{"api_version":"1","generated_at":"2026-04-26T23:31:19+00:00","cve":"CVE-2023-3937","urls":{"html":"https://cve.report/CVE-2023-3937","api":"https://cve.report/api/cve/CVE-2023-3937.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-3937","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-3937"},"summary":{"title":"CVE-2023-3937","description":"Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser","state":"PUBLIC","assigner":"security@snowsoftware.com","published_at":"2023-08-11 12:15:00","updated_at":"2023-08-18 14:30:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC","name":"https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC","refsource":"MISC","tags":[],"title":"Snow Globe Community","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-3937","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3937","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"3937","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"3937","vulnerable":"1","versionEndIncluding":"9.30.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"snowsoftware","cpe5":"snow_license_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"service_provider","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-3937","ASSIGNER":"security@snowsoftware.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","cweId":"CWE-79"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Snow Software","product":{"product_data":[{"product_name":"Snow License Manager","version":{"version_data":[{"version_affected":"<=","version_name":"9.0.0","version_value":"9.30.1"}]}}]}}]}},"references":{"reference_data":[{"url":"https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC","refsource":"MISC","name":"https://community.snowsoftware.com/s/feed/0D56M00009gUexuSAC"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"discovery":"EXTERNAL"},"solution":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Upgrade to SLM version 9.30.2"}],"value":"Upgrade to SLM version 9.30.2"}],"credits":[{"lang":"en","value":"Can Doğu & Himanshu Giri"}],"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","version":"3.1"}]}},"nvd":{"publishedDate":"2023-08-11 12:15:00","lastModifiedDate":"2023-08-18 14:30:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.7,"impactScore":2.7}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:snowsoftware:snow_license_manager:*:*:*:*:service_provider:*:*:*","versionStartIncluding":"9.0.0","versionEndIncluding":"9.30.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":null,"notes":[]}}}