Saviynt End-of-Life OVA Connect Installer Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the End of Life (EOL) OVA-based connect installer component, which is used for installations in customer networks. This component was deprecated in September 2023, with support extended until January 2024. The vulnerability arises from improper input neutralization, allowing an actor to manipulate the action parameter of the login form to inject malicious scripts, potentially leading to an XSS attack under certain conditions.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
