Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.
An attacker without any authentication can inject malicious JavaScript code, which is permanently stored (stored) in the Ivanti Endpoint Manager application. The script is then automatically executed in the browser of a logged-in administrator when the infected content is displayed. The attack requires user (administrator) interaction, such as visiting a specific page or view in the management panel. Because the payload operates in the context of a privileged session, the attacker can perform operations with administrator privileges.
An attacker can execute arbitrary JavaScript code in the context of an administrator's session, which in practice can lead to account takeover, theft of authentication credentials, modification of endpoint management environment configuration, or further lateral movement in the network.
Ivanti Endpoint Manager should be updated to version 2024 SU4 SR1 or later. Details are available in the vendor's official security bulletin: https://forums.ivanti.com/s/article/Security-Advisory-EPM-December-2025-for-EPM-2024
Ivanti Endpoint Manager in versions prior to 2024 SU4 SR1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HIvanti Endpoint Manager
APPIvanti2024< 2024
Related vulnerabilities
Absolute Path Traversal w Ivanti EPM — wyciek wrażliwych danych bez uwierzytelnienia
Absolute Path Traversal w Ivanti EPM — wyciek wrażliwych danych bez uwierzytelnienia
Absolute Path Traversal w Ivanti EPM — wyciek danych bez uwierzytelnienia
Absolute Path Traversal w Ivanti Endpoint Manager — wyciek danych bez uwierzytelnienia
SQL Injection w Ivanti Endpoint Manager umożliwiający RCE bez uwierzytelnienia