Cross-Site Scripting Flaw in Absolute Secure Access Console
CVE-2024-37343

5.4MEDIUM

Key Information:

Vendor

Absolute

Vendor
CVE Published:
20 June 2024

What is CVE-2024-37343?

A cross-site scripting vulnerability exists in the administrative console of Absolute Secure Access prior to version 13.06. This issue allows attackers with valid tunnel credentials to inject a limited-length script into the console. The malicious script can be executed when an administrator, using a non-default configuration, inadvertently clicks on it during an active tunnel session. While the confidentiality of the system remains intact, the vulnerability poses significant risks to system integrity.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.