A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.
CVSS
No CVSS.
References
Configurations
History
23 Jun 2025, 20:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://portswigger.net/web-security/cross-site-scripting/stored - Technical Description | |
References | () https://github.com/gabriel-bri/vulnerability-research/tree/main/CVE-2024-55199 - Exploit | |
First Time |
Celk celk Saude
Celk |
|
CPE | cpe:2.3:a:celk:celk_saude:3.1.252.1:*:*:*:*:*:*:* |
10 Mar 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-10 18:15
Updated : 2025-06-23 20:10
NVD link : CVE-2024-55199
Mitre link : CVE-2024-55199
JSON object : View
Products Affected
celk
- celk_saude
CWE
No CWE.