Описание
A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:celk:celk_saude:3.1.252.1:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.00039
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
github
11 месяцев назад
A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.
EPSS
Процентиль: 12%
0.00039
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79