CVE-2024-28979: XSS
Published May 1, 2024
·Updated
Dell OpenManage Enterprise, versions 4.1.0 and older, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Affected Software
1 affected component
Dell OpenManage Enterprise<4.1.0
Event History
May 1, 2024
CVE Published
via MITRE·04:03 AM
Data Sourced
via MITRE·04:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28979?
CVE-2024-28979 is classified as a high severity vulnerability.
2
How do I fix CVE-2024-28979?
To mitigate CVE-2024-28979, upgrade to a version of Dell OpenManage Enterprise that is later than 4.1.0.
3
Who is affected by CVE-2024-28979?
CVE-2024-28979 affects Dell OpenManage Enterprise versions 4.1.0 and older.
4
What type of vulnerability is CVE-2024-28979?
CVE-2024-28979 is an Improper Neutralization of Input During Web Page Generation, leading to Cross-site Scripting.
5
Can a remote attacker exploit CVE-2024-28979?
Yes, a high privileged attacker with remote access can potentially exploit CVE-2024-28979.