Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.
| Software | From | Fixed in |
|---|---|---|
| ivanti / endpoint_manager | - | 2024 |
| ivanti / endpoint_manager | 2024 | 2024.x |
| ivanti / endpoint_manager | 2024-su1 | 2024-su1.x |
| ivanti / endpoint_manager | 2024-su2 | 2024-su2.x |
| ivanti / endpoint_manager | 2024-su3 | 2024-su3.x |
| ivanti / endpoint_manager | 2024-su3_security_release_1 | 2024-su3_security_release_1.x |
| ivanti / endpoint_manager | 2024-su4 | 2024-su4.x |