
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A cross-site scripting (XSS) vulnerability has been identified in the PingFederate Administrative Console, tracked as CVE-2024-25573. The vulnerability allows unsanitized user-supplied data to be saved in the console, which could subsequently trigger the execution of JavaScript code during user processing (NVD).
The vulnerability has been assigned a CVSS v4.0 score of 6.9 (MEDIUM) with the following vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/S:P/AU:N/R:U/RE:M/U:Red. The issue specifically relates to the handling of user-supplied data in the Administrative Console, where insufficient sanitization of input allows for the persistence and subsequent execution of malicious JavaScript code (NVD).
If exploited, this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of other users' sessions when they access the affected Administrative Console. This could potentially lead to unauthorized access to sensitive information or administrative functions (NVD).
Users are advised to refer to the PingFederate release notes and documentation for mitigation steps and updates (PingFederate Docs, PingFederate Downloads).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”