CyberArk Endpoint Privilege Manager
cpe:2.3:a:cyberark:endpoint_privilege_manager:*:*:*:*:*:*:*
- 24.7.1
A code injection vulnerability has been identified in CyberArk Endpoint Privilege Manager SaaS version 24.7.1. An attacker with access to the Administration panel's 'Role Management' tab can inject code by adding a new role in the 'name' field. However, exploiting this vulnerability carries a reduced risk due to the need to bypass the Content-Security-Policy, which prevents JavaScript execution while still allowing HTML injection.
Exploitation of this vulnerability allows for HTML injection, which could be leveraged for Cross-site Scripting (XSS) attacks, according to the CVE-2025-22270 reference.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.