It is possible to inject HTML code into the page content...
Low severity
Unreviewed
Published
Feb 28, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Feb 28, 2025
Published to the GitHub Advisory Database
Feb 28, 2025
It is possible to inject HTML code into the page content using the "content" field in the "Application definition" page.
This issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.
References