Fiche vulnérabilité
CVE-2024-55926 : faille critique xerox workplace suite (CVSS 9.8)
Description
A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 23 janv. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- xerox workplace suite