CVE-2024-13830
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Feb 11, 2025
Updated: Feb 13, 2025
CWE ID 79
Summary
CVE-2024-13830 is a newly disclosed Reflected Cross-Site Scripting (XSS) vulnerability affecting Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3. This issue enables a remote, unauthenticated attacker to inject malicious code into the web application, which, when accessed by an unsuspecting user, can result in the attacker gaining administrative privileges. User interaction is essential for successful exploitation of this weakness.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Ivanti Connect Secure
- Ivanti Policy Secure
Affected Vendors
- Ivanti Software