CVE-2024-56472
05.02.2025, 23:15
IBM Aspera Shares1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Vendor | Product | Version |
---|---|---|
ibm | aspera_shares | 1.9.0 ≤ 𝑥 < 1.10.0 |
ibm | aspera_shares | 1.10.0 |
ibm | aspera_shares | 1.10.0:patch_level1 |
ibm | aspera_shares | 1.10.0:patch_level2 |
ibm | aspera_shares | 1.10.0:patch_level3 |
ibm | aspera_shares | 1.10.0:patch_level4 |
ibm | aspera_shares | 1.10.0:patch_level5 |
ibm | aspera_shares | 1.10.0:patch_level6 |
𝑥
= Vulnerable software versions