A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields. The product name is SAS Web Administration interface (SASAdmin). For the product release, the reported version is 9.4_M2 and the fixed version is 9.4_M3. For the SAS release, the reported version is 9.4 TS1M2 and the fixed version is 9.4 TS1M3.
References
Link | Resource |
---|---|
https://medium.com/%40williamamorim256/stored-xss-vulnerability-discovered-in-sas-9-4-admin-console-5680e9e4062c | |
https://medium.com/%40williamamorim256/stored-xss-vulnerability-discovered-in-sas-9-4-admin-console-5680e9e4062c | |
https://owasp.org/www-community/attacks/xss/ | Third Party Advisory |
https://owasp.org/www-community/attacks/xss/ | Third Party Advisory |
https://support.sas.com/kb/55/539.html | Mitigation Vendor Advisory |
https://support.sas.com/kb/55/539.html | Mitigation Vendor Advisory |
Configurations
History
18 Feb 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.sas.com/kb/55/539.html - Mitigation, Vendor Advisory | |
References | () https://owasp.org/www-community/attacks/xss/ - Third Party Advisory |
07 Nov 2023, 04:08
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
11 Apr 2023, 15:46
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://owasp.org/www-community/attacks/xss/ - Third Party Advisory | |
References | (MISC) https://medium.com/@williamamorim256/stored-xss-vulnerability-discovered-in-sas-9-4-admin-console-5680e9e4062c - Exploit, Third Party Advisory | |
References | (CONFIRM) https://support.sas.com/kb/55/539.html - Mitigation, Vendor Advisory | |
CPE | cpe:2.3:a:sas:web_administration_interface:9.4:m2:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
First Time |
Sas web Administration Interface
Sas |
|
CWE | CWE-79 |
05 Apr 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
Summary | A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields. The product name is SAS Web Administration interface (SASAdmin). For the product release, the reported version is 9.4_M2 and the fixed version is 9.4_M3. For the SAS release, the reported version is 9.4 TS1M2 and the fixed version is 9.4 TS1M3. | |
References |
|
05 Apr 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
Summary | ** DISPUTED ** A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields. NOTE: the vendor's position is that this report "does not contain adequate or accurate information about affected product versions or the nature of the exploit itself." |
03 Apr 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-03 22:15
Updated : 2025-02-18 15:15
NVD link : CVE-2023-24724
Mitre link : CVE-2023-24724
JSON object : View
Products Affected
sas
- web_administration_interface
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')