CVE-2024-51026: Netadmin

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field.

Affected products

  • Netadmin Netadmin: version 4.0.30319 only

Published 2024-11-11. Last modified 2026-06-17.