Cross-Site Scripting Vulnerability in Absolute Secure Access Management UI
CVE-2024-37351

3.4LOW

Key Information:

Vendor

Absolute

Vendor
CVE Published:
20 June 2024

What is CVE-2024-37351?

A cross-site scripting vulnerability exists in the management UI of Absolute Secure Access, allowing attackers with administrator permissions to disrupt the management UI's functionality. This occurs when multiple administrators attempt to edit the same management object, potentially leading to conflicts and misuse. While there is no compromise of confidentiality or system availability, the integrity of the system is at risk. Users are encouraged to update to Absolute Secure Access version 13.06 or later to mitigate this vulnerability.

References

CVSS V3.1

Score:
3.4
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.