Vulnerability Description
Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://omadaidentity.com
- https://r.sec-consult.com/omada
- https://sec-consult.com/vulnerability-lab/advisory/stored-cross-site-scripting-i
- http://seclists.org/fulldisclosure/2024/Nov/19
FAQ
What is CVE-2024-52951?
CVE-2024-52951 is a vulnerability with a CVSS score of 8.0 (HIGH). Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a speci...
How severe is CVE-2024-52951?
CVE-2024-52951 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-52951?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.