CVE-2024-22238

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
06/02/2024
Last modified:
03/06/2025

Description

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:aria_operations_for_networks:*:*:*:*:*:*:*:* 6.0.0 (including) 6.12.0 (including)