Description
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-45978 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user. |
References
| Link | Providers |
|---|---|
| https://www.veritas.com/support/en_US/security/VTS24-013 |
|
History
Tue, 19 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Veritas
Veritas enterprise Vault |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:veritas:enterprise_vault:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Veritas
Veritas enterprise Vault |
|
| Metrics |
ssvc
|
Mon, 18 Nov 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-19T15:49:04.266Z
Reserved: 2024-11-18T00:00:00.000Z
Link: CVE-2024-52944
Updated: 2024-11-19T15:46:26.253Z
Status : Analyzed
Published: 2024-11-18T06:15:06.017
Modified: 2025-04-30T16:19:05.470
Link: CVE-2024-52944
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD