PT-2025-48212 · Alc+1 · Alc Webctrl+1

Inacio Santos

+1

·

Published

2025-11-27

·

Updated

2025-11-27

·

CVE-2024-5540

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ALC WebCTRL and Carrier i-Vu versions prior to 8.0
Description A reflective cross-site scripting issue exists in login panels. This allows a malicious actor to compromise the client browser.
Recommendations Update ALC WebCTRL and Carrier i-Vu to version 8.0 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-5540

Affected Products

Alc Webctrl
Carrier I-Vu