Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-22901 | Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing. |
Mon, 16 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 15 Jun 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing. | |
| Title | Stored Cross-Site Scripting in Administrative Console Context | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Ping Identity
Published:
Updated: 2025-06-16T18:05:43.793Z
Reserved: 2024-02-29T23:52:30.507Z
Link: CVE-2024-25573
Updated: 2025-06-16T18:05:39.655Z
Status : Deferred
Published: 2025-06-15T16:15:18.683
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-25573
No data.
OpenCVE Enrichment
No data.
EUVD