PT-2024-30178 · Incognito · Incognito Service Activation Center (Sac) Ui

Etienne Supra

·

Published

2024-11-13

·

Updated

2024-11-18

·

CVE-2024-42834

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Incognito Service Activation Center (SAC) UI version 14.11
Description A stored cross-site scripting (XSS) issue in the Create Customer API allows authenticated attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the lastName parameter. This enables attackers to potentially manipulate the web application's behavior.
Recommendations For Incognito Service Activation Center (SAC) UI version 14.11, consider restricting access to the Create Customer API until a fix is available, and avoid using the lastName parameter in this API endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-42834

Affected Products

Incognito Service Activation Center (Sac) Ui