Cross-Site Scripting in IBM Aspera Shares Affects User Security
CVE-2024-38317
4.8MEDIUM
Summary
IBM Aspera Shares versions 1.9.0 through 1.10.0 PL6 are susceptible to a cross-site scripting (XSS) vulnerability. This issue allows a privileged user to inject arbitrary JavaScript code into the Web UI. Such exploitation can modify the intended functionality of the application, potentially leading to the exposure of sensitive user credentials within a trusted session.
Affected Version(s)
Aspera Shares 1.9.0 <= 1.10.0 PL6
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved