sk183054 - CVE-2024-52887 - Self-XSS vulnerability in Mobile Access Native Applications 'favorites' dialog
CVE-2024-52887 - Self-XSS vulnerability in Mobile Access Native Applications 'favorites' dialog
Please read this important update from Check Point.
Security Alert:
- Level: Low
- Product: Mobile Access / SSL VPN
- Version: R81.10 (EOS), R81.20, R82
- OS: Gaia
- Last Modified: 2025-04-27
Symptoms
- The Mobile Access portal is vulnerable to a stored, self-XSS attack.
An authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.
So far today, no attack with actual impact is known.
- This issue received the ID CVE-2024-52887
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 14
- Jumbo Hotfix Accumulator for R81.20 starting from Take 99
- Jumbo Hotfix Accumulator for R81.10 starting from Take 173
Article Properties
- Access Level: General
- Severity: Low
- Status: Approved
- Date Created: 2025-01-29
- Last Modified: 2025-04-27