cve/2024/CVE-2024-37348.md
2025-09-29 21:09:30 +02:00

1.1 KiB
Raw Permalink Blame History

CVE-2024-37348

Description

There is a cross-sitescripting vulnerability in the management UI of Absolute Secure Access prior toversion 13.06. Attackers with system administrator permissions can interferewith another system administrators use of the management UI when the secondadministrator later edits the same management object. This vulnerability isdistinct from CVE-2024-37349 and CVE-2024-37351. The scope is unchanged,there is no loss of confidentiality. Impact to system integrity is high, impactto system availability is none.

POC

Reference

No PoCs from references.

Github