First published: Thu Nov 28 2024(Updated: )
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE manager allows attackers to execute Javascript code in the organization credentials sub page. This issue affects Container suse/manager/5.0/x86_64/server:5.0.2.7.8.1: before 5.0.15-150600.3.10.2; SUSE Manager Server Module 4.3: before 4.3.42-150400.3.52.1.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Manager | <5.0.15-150600.3.10.2 | |
SUSE Manager Server Module | <4.3.42-150400.3.52.1 | |
SUSE Spacewalk |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49503 is classified as a high severity vulnerability due to its potential for executing arbitrary JavaScript code.
To fix CVE-2024-49503, upgrade SUSE Manager to version 5.0.15 or later, or apply the necessary security patches.
CVE-2024-49503 affects SUSE Manager versions prior to 5.0.15 and SUSE Manager Server Module versions prior to 4.3.42.
CVE-2024-49503 is an Improper Neutralization of Input During Web Page Generation vulnerability, specifically an XSS vulnerability.
Yes, CVE-2024-49503 can compromise organizational credentials and lead to unauthorized access, posing a significant security risk.