First published: Mon Nov 18 2024(Updated: )
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Enterprise Vault | <15.1 UPD882911 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52943 is considered a medium severity vulnerability due to its potential to exploit cross-site scripting in authenticated sessions.
To fix CVE-2024-52943, update Veritas Enterprise Vault to version 15.1 UPD882912 or later to mitigate the XSS vulnerability.
CVE-2024-52943 allows an authenticated remote attacker to perform Cross-Site Scripting (XSS) attacks via specially crafted HTTP requests.
CVE-2024-52943 affects users of Veritas Enterprise Vault versions prior to 15.1 UPD882911.
The exploitation of CVE-2024-52943 can lead to unauthorized script execution within the context of an authenticated user session, compromising user data.