PT-2024-35498 · Omada · Omada Identity
Daniel Hirschberger
·
Published
2024-11-27
·
Updated
2024-11-27
·
CVE-2024-52951
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Omada Identity versions prior to 15 update 1
Description:
The issue allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History. This is a result of a Stored Cross-Site Scripting in the Access Request History.
Recommendations:
For Omada Identity versions prior to 15 update 1, update to version 15 update 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Access Request History feature until a patch is applied. Avoid using manipulated links or viewing suspicious Access Request History entries to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Omada Identity