Cross-Site Scripting (XSS) Vulnerability in End of Life OVA Connect Installer
An End of Life (EOL) OVA based connect installer component, used for network installation, has a vulnerability involving improper neutralization of input. This deprecated component, which was phased out in September 2023 with support ending in January 2024, allows an actor to manipulate the login form's action parameter. By injecting malicious scripts through this parameter, an attacker could potentially execute a Cross Site Scripting (XSS) attack under specific conditions.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
saviynt ova based connect |