PT-2024-33539 · Suse · Suse Manager Server Module+2

Paolo Perego

·

Published

2024-11-18

·

Updated

2024-11-28

·

CVE-2024-49503

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SUSE Manager Server Module versions prior to 4.3.42-150400.3.52.1 Container suse/manager/5.0/x86 64/server versions prior to 5.0.15-150600.3.10.2
Description A Cross-site Scripting (XSS) issue allows attackers to execute JavaScript code in the organization credentials sub-page. This can be exploited by attackers to run malicious scripts remotely.
Recommendations For Container suse/manager/5.0/x86 64/server versions prior to 5.0.15-150600.3.10.2, update to version 5.0.15-150600.3.10.2 or later. For SUSE Manager Server Module versions prior to 4.3.42-150400.3.52.1, update to version 4.3.42-150400.3.52.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-49503
OPENSUSE-SU-2024_4007-1
SUSE-SU-2024:4006-1
SUSE-SU-2024:4007-1

Affected Products

Suse Manager Server Module
Suse
Suse/Manager/5.0/X86 64/Server