fleetdm/fleet
cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*
- <= 4.78.1
A cross-site scripting (XSS) vulnerability has been identified in Fleet device management software, specifically in versions prior to 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3. When Windows Mobile Device Management (MDM) is enabled, an unauthenticated attacker can exploit this vulnerability to steal an administrator's authentication token from localStorage. This could lead to unauthorized access to Fleet, including administrative privileges, visibility into device data, and the ability to modify configurations. The vulnerability does not allow unauthenticated access and is not present when Windows MDM is disabled.
Exploitation of this vulnerability could allow an attacker to retrieve a Fleet administrator's authentication token, potentially leading to unauthorized administrative access on the Fleet platform. This access would include the ability to view and manage device data and configurations. Additionally, according to the advisory, such exploitation could allow an attacker to deploy scripts to managed hosts.
Users can upgrade to Fleet versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, or 4.53.3 to address this vulnerability. If an immediate upgrade is not possible, Windows MDM can be temporarily disabled.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.