Description
A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54263 | A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser. |
References
History
Mon, 23 Jun 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Celk
Celk celk Saude |
|
| CPEs | cpe:2.3:a:celk:celk_saude:3.1.252.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Celk
Celk celk Saude |
Mon, 10 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 10 Mar 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-10T18:02:08.891Z
Reserved: 2024-12-06T00:00:00.000Z
Link: CVE-2024-55199
Updated: 2025-03-10T18:02:03.297Z
Status : Analyzed
Published: 2025-03-10T18:15:29.757
Modified: 2025-06-23T20:10:31.250
Link: CVE-2024-55199
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD