Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2022 SU6
- <= 2024
A reflected cross-site scripting vulnerability has been identified in Ivanti Endpoint Manager versions prior to 2024 SU1 and 2022 SU7. This vulnerability allows remote, unauthenticated attackers to execute arbitrary JavaScript in the context of the victim's browser, with only minimal user interaction required.
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can execute malicious scripts in the context of the user's browser session.
Users can upgrade to Ivanti Endpoint Manager 2024 SU2 or 2022 SU8 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.