Authenticated Data Attack via HTTP Request Sanitization Denial
CVE-2024-47854
6.1MEDIUM
Key Information:
- Vendor
Veritas
- Status
- Vendor
- CVE Published:
- 4 October 2024
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2024-47854?
An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.