CVE-2024-49502: Reflected XSS in Setup Wizard, HTTP Proxy credentials pane in spacewalk-web
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows attackers to attack users by providing specially crafted URLs to click. This issue affects Container suse/manager/5.0/x8664/server:5.0.2.7.8.1: before 5.0.15-150600.3.10.2; SUSE Manager Server Module 4.3: before 4.3.42-150400.3.52.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49502?
CVE-2024-49502 is considered a moderate severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2024-49502?
To fix CVE-2024-49502, you should update to the latest version of SUSE Manager or SUSE Manager Server Module as provided by the vendor.
Which software is affected by CVE-2024-49502?
CVE-2024-49502 affects SUSE Manager up to version 5.0.15-150600.3.10.2 and SUSE Manager Server Module up to version 4.3.42-150400.3.52.1.
What type of vulnerability is CVE-2024-49502?
CVE-2024-49502 is classified as an Improper Neutralization of Input During Web Page Generation, resulting in Cross-site Scripting (XSS).
Can CVE-2024-49502 be exploited by attackers?
Yes, CVE-2024-49502 can be exploited by attackers through specially crafted URLs targeting the HTTP Proxy credentials pane.