Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-37345

Опубликовано: 20 июн. 2024
Источник: nvd
CVSS3: 5.3
CVSS3: 5.4
EPSS Низкий

Описание

There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length script to the administrative UI which is then stored where an administrator can access it. The scope is unchanged, there is no loss of confidentiality. Impact to system availability is none, impact to system integrity is high

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*
Версия до 13.06 (исключая)

EPSS

Процентиль: 53%
0.00296
Низкий

5.3 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.3
github
больше 1 года назад

There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length script to the administrative UI which is then stored where an administrator can access it. The scope is unchanged, there is no loss of confidentiality. Impact to system availability is none, impact to system integrity is high

EPSS

Процентиль: 53%
0.00296
Низкий

5.3 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79