CVE-2024-40875: Cross-site scripting vulnerability in the Secure Access administrative console prior to 13.52
There is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.52. Attackers with system administrator permissions can interfere with another system administrator’s use of the management console when the second administrator logs in. Attack complexity is high, attack requirements are present, privileges required are high, user interaction required is none. The impact to confidentiality is none, the impact to availability is low, and the impact to system integrity is high.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40875?
CVE-2024-40875 is classified as a cross-site scripting vulnerability with potentially high severity due to the impact on system administrators.
How do I fix CVE-2024-40875?
To fix CVE-2024-40875, upgrade Absolute Secure Access to version 13.52 or later.
Who is affected by CVE-2024-40875?
CVE-2024-40875 affects users of Absolute Secure Access prior to version 13.52 with system administrator permissions.
What type of vulnerability is CVE-2024-40875?
CVE-2024-40875 is a cross-site scripting (XSS) vulnerability.
Can CVE-2024-40875 be exploited remotely?
Yes, an attacker with system administrator permissions can exploit CVE-2024-40875 to interfere with another administrator's session.