PT-2024-36337 · Kurmi · Kurmi Provisioning Suite

CVE-2024-54451

·

Published

2024-12-27

·

Updated

2024-12-28

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Kurmi Provisioning Suite versions 7.9.0.38 and earlier Kurmi Provisioning Suite versions 7.10.x through 7.10.0.18 Kurmi Provisioning Suite versions 7.11.x through 7.11.0.15
Description: A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page allows remote attackers, authenticated as system administrators, to inject arbitrary web script or HTML via the COMPONENT fields(htmlTitle) field. This field is rendered in other pages of the application for all users if the graphical customization has been activated by a super-administrator.
Recommendations: For Kurmi Provisioning Suite versions 7.9.0.38 and earlier, update to version 7.9.0.39 or later. For Kurmi Provisioning Suite versions 7.10.x through 7.10.0.18, update to version 7.10.0.19 or later. For Kurmi Provisioning Suite versions 7.11.x through 7.11.0.15, update to version 7.11.0.16 or later. As a temporary workaround, consider restricting access to the graphicCustomization.do page until a patch is available. Avoid using the COMPONENT fields(htmlTitle) field in the graphicCustomization.do page until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-54451

Affected Products

Kurmi Provisioning Suite