First published: Tue Nov 26 2024(Updated: )
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vRealize Operations |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38833 has been assessed with a severity rating that indicates a significant security risk due to stored cross-site scripting.
To mitigate CVE-2024-38833, apply the latest security patch provided by VMware for Aria Operations.
CVE-2024-38833 is categorized as a stored cross-site scripting vulnerability.
Organizations using VMware Aria Operations that have configured editable email templates are at risk from CVE-2024-38833.
CVE-2024-38833 could allow an attacker to inject malicious scripts, leading to unauthorized access or data manipulation.