First published: Thu Nov 28 2024(Updated: )
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows attackers to attack users by providing specially crafted URLs to click. This issue affects Container suse/manager/5.0/x86_64/server:5.0.2.7.8.1: before 5.0.15-150600.3.10.2; SUSE Manager Server Module 4.3: before 4.3.42-150400.3.52.1.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Manager Server | <5.0.15-150600.3.10.2 | |
SUSE Manager | <4.3.42-150400.3.52.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49502 is considered a moderate severity vulnerability due to its potential for XSS attacks.
To fix CVE-2024-49502, you should update to the latest version of SUSE Manager or SUSE Manager Server Module as provided by the vendor.
CVE-2024-49502 affects SUSE Manager up to version 5.0.15-150600.3.10.2 and SUSE Manager Server Module up to version 4.3.42-150400.3.52.1.
CVE-2024-49502 is classified as an Improper Neutralization of Input During Web Page Generation, resulting in Cross-site Scripting (XSS).
Yes, CVE-2024-49502 can be exploited by attackers through specially crafted URLs targeting the HTTP Proxy credentials pane.