CVE-2024-52951: Omada Identity
High severity, CVSS 8.0. EPSS: 1.1% chance of exploitation in the next 30 days.
Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History
Affected products
- Omada Omada Identity: before 15 (fixed in 15)
Published 2024-11-27. Last modified 2026-06-17.