CVE-2024-49502: Reflected XSS in Setup Wizard, HTTP Proxy credentials pane in spacewalk-web

4.6 CVSS

Description

A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows attackers to attack users by providing specially crafted URLs to click.
This issue affects Container suse/manager/5.0/x86_64/server:5.0.2.7.8.1: before 5.0.15-150600.3.10.2; SUSE Manager Server Module 4.3: before 4.3.42-150400.3.52.1.

Classification

CVE ID: CVE-2024-49502

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.6

Affected Products

Vendor: SUSE

Product: Container suse/manager/5.0/x86_64/server:5.0.2.7.8.1

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-49502

Timeline