It is possible to inject HTML code into the page content using the "content" field in the "Application definition" page. This issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.
History

Fri, 28 Feb 2025 13:00:00 +0000

Type Values Removed Values Added
Description It is possible to inject HTML code into the page content using the "content" field in the "Application definition" page. This issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.
Title HTML injection in CyberArk Endpoint Privilege Manager
Weaknesses CWE-80
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2025-02-28T12:34:08.548Z

Updated: 2025-03-05T15:53:46.747Z

Reserved: 2025-01-02T13:12:19.642Z

Link: CVE-2025-22274

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-28T13:15:28.067

Modified: 2025-03-05T16:15:38.243

Link: CVE-2025-22274

cve-icon Redhat

No data.