#VU98759 Stored cross-site scripting in BIG-IQ Centralized Management - CVE-2024-47139
Published: October 16, 2024
BIG-IQ Centralized Management
F5 Networks
Description
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data within the BIG-IQ user interface. A remote user can inject and execute arbitrary JavaScript code in victim's browser in the security context of the web interface.