Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-45976 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user. |
| Link | Providers |
|---|---|
| https://www.veritas.com/support/en_US/security/VTS24-013 |
|
Wed, 30 Apr 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Veritas
Veritas enterprise Vault |
|
| CPEs | cpe:2.3:a:veritas:enterprise_vault:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Veritas
Veritas enterprise Vault |
Mon, 18 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
ssvc
|
Mon, 18 Nov 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization if executed by that user. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-18T15:51:21.931Z
Reserved: 2024-11-18T00:00:00.000Z
Link: CVE-2024-52942
Updated: 2024-11-18T15:51:15.603Z
Status : Analyzed
Published: 2024-11-18T06:15:05.543
Modified: 2025-04-30T16:18:43.660
Link: CVE-2024-52942
No data.
OpenCVE Enrichment
No data.
EUVD