Reflective Cross-Site Scripting in ALC WebCTRL and Carrier i-Vu
CVE-2024-5540
6.9MEDIUM
What is CVE-2024-5540?
A reflective cross-site scripting vulnerability exists in ALC WebCTRL and Carrier i-Vu in any version prior to 8.0. This flaw allows malicious actors to execute scripts in the context of the user’s session via compromised login panels. This can lead to potential exploitation, making it crucial for users to upgrade their systems to mitigate risks associated with this vulnerability.
Affected Version(s)
i-Vu Windows 0 < 8.0
WebCTRL Windows 0 < 8.0
