CVE-2024-1606

CVSS V2 None CVSS V3 None
Description
Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. This might lead to a successful phishing attack for example by tricking users into using a hyperlink pointing to a website controlled by an attacker. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.200.
Overview
  • CVE ID
  • CVE-2024-1606
  • Assigner
  • CERT-PL
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-03-18T10:00:05.221Z
  • Last Modified Date
  • 2024-03-18T10:00:05.221Z
References
History
Created Old Value New Value Data Type Notes
2024-06-26 05:57:24 Added to TrackCVE