Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.
CVE ID: CVE-2024-0589
Vendor: Devolutions
Product: Remote Desktop Manager
EPSS Score: 0.37% (probability of being exploited)
EPSS Percentile: 57.98% (scored less or equal to compared to others)
EPSS Date: 2025-06-14 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false