CVE-2024-49503: Reflected XSS in Setup Wizard, Organization Credentials in spacewalk-web
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE manager allows attackers to execute Javascript code in the organization credentials sub page. This issue affects Container suse/manager/5.0/x8664/server:5.0.2.7.8.1: before 5.0.15-150600.3.10.2; SUSE Manager Server Module 4.3: before 4.3.42-150400.3.52.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49503?
CVE-2024-49503 is classified as a high severity vulnerability due to its potential for executing arbitrary JavaScript code.
How do I fix CVE-2024-49503?
To fix CVE-2024-49503, upgrade SUSE Manager to version 5.0.15 or later, or apply the necessary security patches.
Which versions of SUSE Manager are affected by CVE-2024-49503?
CVE-2024-49503 affects SUSE Manager versions prior to 5.0.15 and SUSE Manager Server Module versions prior to 4.3.42.
What type of vulnerability is CVE-2024-49503?
CVE-2024-49503 is an Improper Neutralization of Input During Web Page Generation vulnerability, specifically an XSS vulnerability.
Can CVE-2024-49503 impact organizational security?
Yes, CVE-2024-49503 can compromise organizational credentials and lead to unauthorized access, posing a significant security risk.