CVE-2023-33732: Escanav Escan Management Console

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attacker to inject arbitrary code via the vulnerable parameters type, txtPolicyType, and Deletefileval.

Affected products

  • Escanav Escan Management Console: version 14.0.1400.2281 only

Published 2023-05-31. Last modified 2026-06-17.