CVE-2024-47854

An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:veritas:data_insight:*:*:*:*:*:*:*:*

History

13 Nov 2024, 15:25

Type Values Removed Values Added
CPE cpe:2.3:a:veritas:data_insight:*:*:*:*:*:*:*:*
First Time Veritas
Veritas data Insight
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://www.veritas.com/content/support/en_US/security/VTS24-010 - () https://www.veritas.com/content/support/en_US/security/VTS24-010 - Vendor Advisory

06 Oct 2024, 21:15

Type Values Removed Values Added
Summary A vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user. An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user.

04 Oct 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-04 06:15

Updated : 2024-11-26 16:15


NVD link : CVE-2024-47854

Mitre link : CVE-2024-47854


JSON object : View

Products Affected

veritas

  • data_insight
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')