CVE-2023-40721

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Feb 11, 2025
CWE ID 134

Summary

CVE-2024-13830 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3. This issue allows an unauthenticated remote attacker to inject malicious scripts into a user's browser, gaining admin privileges. User interaction is necessary for the exploitation of this vulnerability, making it a significant risk for affected organizations. To mitigate this threat, it is recommended that users upgrade to the latest version of these Ivanti products as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share