Ivanti Endpoint Manager
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*
- <= 2022 SU6
- <= 2024
A reflected cross-site scripting vulnerability has been identified in Ivanti Endpoint Manager versions prior to 2024 SU1 and 2022 SU7. This vulnerability allows a remote, unauthenticated attacker to gain admin privileges by injecting malicious JavaScript that is executed in the context of the user's browser. Exploitation of this issue requires user interaction.
Exploitation of this vulnerability allows for reflected cross-site scripting, with the injected script executed in the context of the user's browser, potentially leading to unauthorized actions or access within the application.
Users can upgrade to Ivanti Endpoint Manager 2024 SU2 or 2022 SU8 to address this vulnerability. The latest versions are available for download through the Ivanti License System.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.