Ivanti Endpoint Manager Reflected Cross-Site Scripting Vulnerability Allowing Admin Privileges

Vulnerability

A reflected cross-site scripting vulnerability has been identified in Ivanti Endpoint Manager versions prior to 2024 SU1 and 2022 SU7. This vulnerability allows a remote, unauthenticated attacker to gain admin privileges by injecting malicious JavaScript that is executed in the context of the user's browser. Exploitation of this issue requires user interaction.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, with the injected script executed in the context of the user's browser, potentially leading to unauthorized actions or access within the application.

Remediation

Users can upgrade to Ivanti Endpoint Manager 2024 SU2 or 2022 SU8 to address this vulnerability. The latest versions are available for download through the Ivanti License System.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
5.0
exploitability
6.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.