VulnerabilityAnalyzed
CVE-2024-33859
HTML code sent through logs wasn't being escaped in the "Interesting Field" Web UI, leading to XSS.
MEDIUM 6.1EPSS 0.31%
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting Field" Web UI, leading to XSS.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- logpoint/siem
- Source
- cve@mitre.org
References
- https://servicedesk.logpoint.com/hc/en-us/articles/18533927651357-XSS-in-Interesting-Fields-in-Logpoint-Web-UIVendor Advisory
- https://www.logpoint.com/Product
- https://servicedesk.logpoint.com/hc/en-us/articles/18533927651357-XSS-in-Interesting-Fields-in-Logpoint-Web-UIVendor Advisory
- https://www.logpoint.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.