← Back to browse · API

CVE-2024-11773

Severity
CRITICAL
CVSS
9.1
EPSS
0.23598
Risk score
44.66
CISA KEV
No
PoC
No
Published
2024-12-10
Modified
2024-12-14
First seen
2026-08-07
Aliases
EUVD-2024-34196, GHSA-XX9R-4WQJ-799Q
Products
Ivanti:Cloud Services Application patch: 5.0.3
Sources
euvd EUVD-2024-34196

Description

SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

References