{ "id": "CVE-2024-22397", "sourceIdentifier": "PSIRT@sonicwall.com", "published": "2024-03-14T04:15:09.297", "lastModified": "2024-11-21T08:56:11.887", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code." }, { "lang": "es", "value": "La neutralizaci\u00f3n inadecuada de la entrada durante la generaci\u00f3n de la p\u00e1gina web (\"Cross-site Scripting\") en el portal SonicOS SSLVPN permite a un atacante remoto autenticado como usuario \"administrador\" del firewall almacenar y ejecutar c\u00f3digo JavaScript arbitrario." } ], "metrics": {}, "weaknesses": [ { "source": "PSIRT@sonicwall.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "references": [ { "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0005", "source": "PSIRT@sonicwall.com" }, { "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0005", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }