Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-45975 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user. |
| Link | Providers |
|---|---|
| https://www.veritas.com/support/en_US/security/VTS24-013 |
|
Sat, 26 Jul 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Veritas
Veritas enterprise Vault |
|
| Vendors & Products |
Veritas
Veritas enterprise Vault |
Mon, 18 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
ssvc
|
Mon, 18 Nov 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-18T15:53:55.041Z
Reserved: 2024-11-18T00:00:00.000Z
Link: CVE-2024-52941
Updated: 2024-11-18T15:53:46.848Z
Status : Deferred
Published: 2024-11-18T06:15:05.283
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-52941
No data.
OpenCVE Enrichment
Updated: 2025-07-26T16:47:23Z
EUVD