CVE-2024-24907 HIGH

CVE-2024-24907

Vendor Dell
Product Secure Connect Gateway (SCG) Policy Manager
Weakness CWE-79 · XSS
Published March 1, 2024
Last update August 15, 2024

CVSS base score

7.6/10
Attack vector Adjacent
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability in the Filters page. An adjacent network high privileged attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.

Key dates

02Disclosure timeline

March 1, 2024 CVE published
August 15, 2024 Record updated