Security ID : QSA-25-11
Vulnerability in License Center
- Release date : June 7, 2025 
- CVE identifier : CVE-2024-50406 
- Affected products: License Center 1.9.x 
Severity
Moderate
Status
Resolved
Summary
A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If a remote attacker gains access to a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following version:
| Affected Product | Fixed Version | 
| License Center 1.9.x | License Center 1.9.49 and later | 
Recommendation
To fix the vulnerability, we recommend updating License Center to the latest version.
Updating License Center
- Log on to QTS or QuTS hero as an administrator.
- Open App Center and then click  . .
 A search box appears.
- Type "License Center" and then press ENTER.
 License Center appears in the search results.
- Click Update.
 A confirmation message appears.
 Note: The Update button is not available if your License Center is already up to date.
- Click OK.
 The system updates the application.
Attachment
Acknowledgements: Searat and izut
Revision History: 
V1.0 (June 07, 2025) - Published
 
                                     
                                    