ZDI-CAN-24697: ZDI-24-1660: Veritas Enterprise Vault HTMLView Cross-Site Scripting Vulnerability
This vulnerability allows remote attackers to execute web requests with the target user's privileges on affected installations of Veritas Enterprise Vault. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.3. The following CVEs are assigned: CVE-2024-52943.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24697?
The severity of ZDI-CAN-24697 is critical due to its potential for remote code execution.
How do I fix ZDI-CAN-24697?
To fix ZDI-CAN-24697, you should update Veritas Enterprise Vault to the latest patched version provided by the vendor.
What type of attacks can ZDI-CAN-24697 facilitate?
ZDI-CAN-24697 can facilitate remote code execution attacks by exploiting user privileges.
Is user interaction required to exploit ZDI-CAN-24697?
Yes, user interaction is required as the target must visit a malicious page to exploit ZDI-CAN-24697.
Which software versions are affected by ZDI-CAN-24697?
ZDI-CAN-24697 affects installations of Veritas Enterprise Vault without the latest security updates.