CVE-2024-24907: XSS
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability in the Filters page. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24907?
CVE-2024-24907 is classified as a high-severity stored cross-site scripting vulnerability.
How do I fix CVE-2024-24907?
To fix CVE-2024-24907, update the Dell Secure Connect Gateway to the latest version available after 5.22.00.16.
Who is affected by CVE-2024-24907?
CVE-2024-24907 affects all versions of Dell Secure Connect Gateway (SCG) Policy Manager.
What type of vulnerability is CVE-2024-24907?
CVE-2024-24907 is a stored cross-site scripting vulnerability that allows the storage of malicious HTML or JavaScript.
How can CVE-2024-24907 be exploited?
CVE-2024-24907 can potentially be exploited by a high-privileged attacker on an adjacent network.