PT-2025-5762 · Skybox · Skybox Change Manager

Dan Dorego

·

Published

2025-02-05

·

Updated

2025-02-05

·

CVE-2024-54853

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Skybox Change Manager versions 13.2.170 and earlier
Description A Stored Cross-Site Scripting issue was identified that allows remote authenticated users to store malicious payloads in an affected field, which would then execute in an unsuspecting victim's browser.
Recommendations For Skybox Change Manager versions 13.2.170 and earlier, consider restricting access to the affected field to minimize the risk of exploitation until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-54853

Affected Products

Skybox Change Manager