Security Advisory

CVE-2024-10033

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-10-16 16:59:43
Last updated 2025-11-20 18:11:34
Assigner redhat
State PUBLISHED

Description

A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data.