PT-2024-19564 · Unknown · Ca17 Teamsacs

Fuomag9

·

Published

2024-04-02

·

Updated

2024-12-04

·

CVE-2024-22780

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CA17 TeamsACS version 1.0.1
Description A Cross Site Scripting issue allows a remote attacker to execute arbitrary code via a crafted script to the errmsg parameter. This enables the attacker to perform unauthorized actions on the affected system.
Recommendations For CA17 TeamsACS version 1.0.1, consider restricting access to the errmsg parameter to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the errmsg parameter in sensitive operations. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-22780
GHSA-HWVW-GH23-QPVQ
GO-2024-2684

Affected Products

Ca17 Teamsacs