CVE Database
/

CVE-2024-39717

Back to search

CVE-2024-39717

Published: Aug 22, 2024

Modified: Oct 21, 2025

PUBLISHED

CVSS v3.0

6.6

MEDIUM

Description

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.

VendorProductVersions

Versa

Director

affected
21.2.2 - <= 21.2.2
affected
21.2.3 before 2024-06-21 - < 21.2.3 before 2024-06-21
affected
22.1.1 - <= 22.1.1
affected
22.1.2 before 2024-06-21 - <= 22.1.2 before 2024-06-21
affected
22.1.3 before 2024-06-21 - <= 22.1.3 before 2024-06-21

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

High

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now