mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 01:02:25 +00:00
37 lines
1.2 KiB
JSON
37 lines
1.2 KiB
JSON
{
|
|
"id": "CVE-2024-22397",
|
|
"sourceIdentifier": "PSIRT@sonicwall.com",
|
|
"published": "2024-03-14T04:15:09.297",
|
|
"lastModified": "2024-03-14T12:52:09.877",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "La neutralizaci\u00f3n inadecuada de la entrada durante la generaci\u00f3n de la p\u00e1gina web (\"Cross-site Scripting\") en el portal SonicOS SSLVPN permite a un atacante remoto autenticado como usuario \"administrador\" del firewall almacenar y ejecutar c\u00f3digo JavaScript arbitrario."
|
|
}
|
|
],
|
|
"metrics": {},
|
|
"weaknesses": [
|
|
{
|
|
"source": "PSIRT@sonicwall.com",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-79"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0005",
|
|
"source": "PSIRT@sonicwall.com"
|
|
}
|
|
]
|
|
} |