PT-2024-25698 · Rsa · Archer Platform
Published
2024-05-06
·
Updated
2025-03-18
·
CVE-2024-34090
CVSS v3.1
7.3
High
| Vector | AC:L/AV:N/A:N/C:H/I:H/PR:L/S:U/UI:R |
Name of the Vulnerable Software and Affected Versions
Archer Platform versions prior to 2024.04
Archer Platform version 6.14.0.3 is a fixed release, implying versions prior to 6.14.0.3 are also affected.
Description
An issue was discovered in the Archer Platform, where there is a stored cross-site scripting (XSS) vulnerability. The login banner in the Archer Control Panel (ACP) did not previously escape content appropriately.
Recommendations
For Archer Platform versions prior to 2024.04, update to version 6.14.0.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to the login banner in the Archer Control Panel (ACP) until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Archer Platform