Stored Cross-Site Scripting Vulnerability in Dell SCG Policy Manager Could Lead to Information Disclosure, Session Theft, or Client-Side Request Forgery
CVE-2024-24906
Key Information:
- Vendor
Dell
- Vendor
- CVE Published:
- 1 March 2024
What is CVE-2024-24906?
The vulnerability in Dell Secure Connect Gateway (SCG) Policy Manager comprises a Stored Cross-Site Scripting (XSS) flaw located on the Policy page. This security risk allows an adjacent network attacker with high privileges to introduce harmful HTML or JavaScript codes into a trusted data store utilized by the application. When unsuspecting users access this data through their browsers, the injected malicious scripts are executed, potentially leading to a range of security issues including unauthorized information disclosure, session hijacking, or even client-side request forgery. Users must be vigilant as these exploits can compromise the confidentiality and integrity of their interactions within the web application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Secure Connect Gateway (SCG) Policy Manager < 5.22.00.16
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved