2025-02-16 03:03:51 +00:00

60 lines
2.0 KiB
JSON

{
"id": "CVE-2024-54853",
"sourceIdentifier": "cve@mitre.org",
"published": "2025-02-05T22:15:30.557",
"lastModified": "2025-02-06T16:15:38.767",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A Stored Cross-Site Scripting (XSS) vulnerability was identified affecting Skybox Change Manager versions 13.2.170 and earlier that allows remote authenticated users to store malicious payloads in the affected field that would then execute in an unsuspecting victim's browser."
},
{
"lang": "es",
"value": "Se identific\u00f3 una vulnerabilidad Cross-Site Scripting (XSS) Almacenado que afecta a las versiones 13.2.170 y anteriores de Skybox Change Manager, que permite a usuarios autenticados remotos almacenar payloads maliciosos en el campo afectado que luego se ejecutar\u00eda en el navegador de una v\u00edctima desprevenida."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.3,
"impactScore": 2.7
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://github.com/KoratSec/CVEs/blob/main/CVE-2024-54853.txt",
"source": "cve@mitre.org"
}
]
}