CVE-2024-12223: Stored Cross-site Scripting (XSS) in Nutanix Prism Central
Published Aug 20, 2025
·Updated
Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.
Affected Software
1 affected component
Nutanix Prism Central<2024.3.1
Event History
Aug 20, 2025
CVE Published
via MITRE·12:44 AM
Data Sourced
via MITRE·12:44 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12223?
CVE-2024-12223 has a high severity rating due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2024-12223?
To fix CVE-2024-12223, upgrade Prism Central to version 2024.3.1 or later.
3
Who is affected by CVE-2024-12223?
CVE-2024-12223 affects all versions of Nutanix Prism Central prior to 2024.3.1.
4
What type of attack does CVE-2024-12223 enable?
CVE-2024-12223 enables a stored cross-site scripting attack that can hijack a user's session.
5
What can an attacker do using CVE-2024-12223?
An attacker can perform actions in a victim user's security context by exploiting CVE-2024-12223.