Vulnerabilities > Absolute > Secure Access > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-20 CVE-2024-37350 Cross-site Scripting vulnerability in Absolute Secure Access
There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13.06.
network
low complexity
absolute CWE-79
4.7
2024-06-20 CVE-2024-37343 Cross-site Scripting vulnerability in Absolute Secure Access
There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.06. Attackers with valid tunnel credentials can pass a limited-length script to the administrative console which is then temporarily stored where an administrator using a non-default configuration could click on it while the attacker has a valid tunnel session with the server.
network
low complexity
absolute CWE-79
5.4
2024-06-20 CVE-2024-37345 Cross-site Scripting vulnerability in Absolute Secure Access
There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length script to the administrative UI which is then stored where an administrator can access it.
network
low complexity
absolute CWE-79
5.4
2024-06-20 CVE-2024-37346 Unspecified vulnerability in Absolute Secure Access
There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06.
network
low complexity
absolute
4.9