← Vulnerability feed

Vulnerability record · CVE-2018-12903 · published 26 June 2018

CVE-2018-12903: Cyberark endpoint privilege manager cross-site scripting vulnerability

Cyberark · Endpoint Privilege Manager

In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the VfManager.asmx SelectAccounts->DisplayName screen, a user's groups in ConfigurationPage, the Dialog Title field, and App Group Name in the Application Group Wizard.

5.4 CVSS 3.0 Medium EPSS 0.64% · top 51.5% CWE-79 · Cross-site scripting
5.4CVSS 3.0 base score, v2 3.5
0.64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the VfManager.asmx SelectAccounts->DisplayName screen, a user's groups in ConfigurationPage, the Dialog Title field, and App Group Name in the Application Group Wizard.

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-12903 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-13052Cyberark endpoint privilege manager vulnerabilityIn CyberArk Endpoint Privilege Manager (formerly Viewfinity), Privilege Escalation is possible if the attacker has one process that executes as Admin.EPSS 1.2%8.5CVE-2026-2914Cyberark endpoint privilege manager improper privilege management vulnerabilityCyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation d…EPSS 0.17%7.8CVE-2025-66374Cyberark endpoint privilege manager improper privilege management vulnerabilityCyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administ…EPSS 0.24%7.8CVE-2021-44049Cyberark endpoint privilege manager exposure of resource to wrong sphere vulnerabilityCyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Pro…EPSS 0.40%7.8CVE-2018-14894Cyberark endpoint privilege manager improper privilege management vulnerabilityCyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file) to bypass intended access r…EPSS 1.9%7.0CVE-2019-9627Cyberark endpoint privilege manager out-of-bounds write vulnerabilityA buffer overflow in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10.7 allows an attacker (without…EPSS 0.41%5.5CVE-2020-25738Cyberark endpoint privilege manager uncontrolled search path element vulnerabilityCyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a pro…EPSS 0.44%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed

Source: NIST National Vulnerability Database (record CVE-2018-12903), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.