CVE-2024-54853

A

Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and earlier that allows remote authenticated users to store malicious payloads in the affected field that would then execute in an unsuspecting victim's browser.

Configurations

No configuration.

History

06 Feb 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) Se identificó una vulnerabilidad Cross-Site Scripting (XSS) Almacenado que afecta a las versiones 13.2.170 y anteriores de Skybox Change Manager, que permite a usuarios autenticados remotos almacenar payloads maliciosos en el campo afectado que luego se ejecutaría en el navegador de una víctima desprevenida.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-79

05 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-05 22:15

Updated : 2025-02-06 16:15


NVD link : CVE-2024-54853

Mitre link : CVE-2024-54853

CVE.ORG link : CVE-2024-54853


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')