Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54482 | LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality |
Github GHSA |
GHSA-9cwv-pxcr-hfjc | LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lfedge
Lfedge ekuiper |
|
| CPEs | cpe:2.3:a:lfedge:ekuiper:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfedge
Lfedge ekuiper |
Wed, 14 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 May 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version 2.1.0 user with rights to modificate the service (e.g. kuiperUser role) can inject a cross-site scripting payload into Connection Configuration key `Name` (`confKey`) parameter. After this setup, when any user with access to this service (e.g. admin) tries to delete this key, a payload acts in the victim's browser. Version 2.1.0 fixes the issue. | |
| Title | Stored XSS in Configuration Key Functionality | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-14T13:21:31.315Z
Reserved: 2024-11-06T19:00:26.394Z
Link: CVE-2024-52290
Updated: 2025-05-14T13:21:21.859Z
Status : Analyzed
Published: 2025-05-14T08:15:33.250
Modified: 2025-07-11T16:20:52.177
Link: CVE-2024-52290
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA