Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2024 SU4
A stored cross-site scripting vulnerability has been identified in Ivanti Endpoint Manager (EPM) versions 2024 SU4 and prior. This vulnerability allows remote, unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator session, requiring user interaction to exploit.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user, potentially leading to session hijacking or other malicious actions.
Users can upgrade to Ivanti Endpoint Manager 2024 SU4 SR1, available through the Ivanti License System. For more information on downloading updates, refer to the Ivanti Endpoint Manager Download Guide.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.