PT-2024-24507 · Tenable · Tenable Identity Exposure

Ammarit Thongthua

+1

·

Published

2024-06-03

·

Updated

2024-07-16

·

CVE-2024-3232

CVSS v3.1

7.6

High

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenable Identity Exposure (affected versions not specified)
Description A formula injection issue exists, allowing an authenticated remote attacker with administrative privileges to manipulate application form fields. This could trick another administrator into executing CSV payloads.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-3232

Affected Products

Tenable Identity Exposure