CVE-2024-52951

S

tored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History

Configurations

No configuration.

History

27 Nov 2024, 21:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Nov/19 -

27 Nov 2024, 20:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0

27 Nov 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-27 15:15

Updated : 2024-11-27 21:15


NVD link : CVE-2024-52951

Mitre link : CVE-2024-52951

CVE.ORG link : CVE-2024-52951


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')