AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-54451

MEDIUM · CVSS 4.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-12-27 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.8. It may be remotely exploitable.

CVE
CVE-2024-54451
Severity
MEDIUM
CVSS
4.8
EPSS
0.27%

Original NVD Description

A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0.38, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15 allows remote attackers (authenticated as system administrators) to inject arbitrary web script or HTML via the COMPONENT_fields(htmlTitle) field, which is rendered in other pages of the application for all users (if the graphical customization has been activated by a super-administrator).