CVE-2024-47854

MEDIUM

Veritas Data Insight <7.1 - XSS

Title source: llm
STIX 2.1

Description

An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated user without sanitization if executed by that user.

Scores

CVSS v3 6.1
EPSS 0.0409
EPSS Percentile 88.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
veritas/data_insight 6.0 - 7.1
Published Oct 04, 2024
Tracked Since Feb 18, 2026