Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-54981 Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 24 Aug 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Nutanix
Nutanix prism Central
Vendors & Products Nutanix
Nutanix prism Central

Wed, 20 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 01:15:00 +0000

Type Values Removed Values Added
Description Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.
Title Stored Cross-site Scripting (XSS) in Nutanix Prism Central
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TML

Published:

Updated: 2025-08-20T15:15:34.599Z

Reserved: 2024-12-05T00:48:35.742Z

Link: CVE-2024-12223

cve-icon Vulnrichment

Updated: 2025-08-20T13:57:31.512Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-20T01:15:29.773

Modified: 2025-08-20T14:39:07.860

Link: CVE-2024-12223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-24T22:19:13Z