CVE-2024-13830

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Feb 11, 2025
Updated: Feb 13, 2025
CWE ID 79

Summary

CVE-2024-13830 is a newly disclosed Reflected Cross-Site Scripting (XSS) vulnerability affecting Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3. This issue enables a remote, unauthenticated attacker to inject malicious code into the web application, which, when accessed by an unsuspecting user, can result in the attacker gaining administrative privileges. User interaction is essential for successful exploitation of this weakness.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Ivanti Connect Secure
  • Ivanti Policy Secure

Affected Vendors

  • Ivanti Software