There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.07. Attackers with system administrator permissions can interfere with another system administrator’s use of the publishing UI when the administrators are editing the same management object. The scope is unchanged, there is no loss of confidentiality. Impact to system availability is none, impact to system integrity is high.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Absolute

Published: 2024-07-25T17:19:28.906Z

Updated: 2024-08-02T04:39:55.361Z

Reserved: 2024-07-10T20:40:17.120Z

Link: CVE-2024-40873

cve-icon Vulnrichment

Updated: 2024-08-02T04:39:55.361Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-25T18:15:03.800

Modified: 2024-08-02T19:57:17.407

Link: CVE-2024-40873

cve-icon Redhat

No data.