CVE-2024-13950: Log Injection
Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.; NEXUS Series: through 3.; MATRIX Series: through 3..
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13950?
CVE-2024-13950 is considered a high severity vulnerability due to the potential for attackers to execute malicious scripts.
How do I fix CVE-2024-13950?
To fix CVE-2024-13950, ensure that you update ASPECT software to the latest version that is patched against this vulnerability.
What types of ASPECT software are affected by CVE-2024-13950?
CVE-2024-13950 affects ASPECT-Enterprise, NEXUS Series, and MATRIX Series up to version 3.*.
Can user credentials impact the risk of CVE-2024-13950?
Yes, if administrator credentials are compromised, it increases the risk associated with CVE-2024-13950 significantly.
What is a log injection vulnerability in the context of CVE-2024-13950?
In the context of CVE-2024-13950, a log injection vulnerability allows attackers to inject malicious browser scripts via logs if they gain access through compromised administrator credentials.