Ivanti Endpoint Manager Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2024 SU4 and prior. This vulnerability allows remote, unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator session, requiring user interaction to exploit.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user, potentially leading to session hijacking or other malicious actions.

Remediation

Users can upgrade to Ivanti Endpoint Manager 2024 SU4 SR1, available through the Ivanti License System. For more information on downloading updates, refer to the Ivanti Endpoint Manager Download Guide.

Added: Dec 9, 2025, 8:59 PM
Updated: Dec 9, 2025, 8:59 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
5.0
exploitability
6.0
remediation
7.9
relevance
1.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.