CVE-2024-51026
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
11/11/2024
Last modified:
12/11/2024
Description
The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM



