CVE-2024-22241

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
06/02/2024
Last modified:
03/06/2025

Description

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner and takeover the user account.  

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:aria_operations_for_networks:*:*:*:*:*:*:*:* 6.0.0 (including) 6.12.0 (including)