Логотип exploitDog
bind:CVE-2024-48761
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-48761

Количество 2

Количество 2

nvd логотип

CVE-2024-48761

около 1 года назад

Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-gpj5-h9pc-v6jc

около 1 года назад

The specific component in Celk Saude 3.1.252.1 that processes user input and returns error messages to the client is vulnerable due to improper validation or sanitization of the "erro" parameter. This parameter appears as a response when incorrect credentials are entered during login. The lack of proper validation or sanitization makes the component susceptible to injection attacks, potentially allowing attackers to manipulate the input and exploit the system.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-48761

Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-gpj5-h9pc-v6jc

The specific component in Celk Saude 3.1.252.1 that processes user input and returns error messages to the client is vulnerable due to improper validation or sanitization of the "erro" parameter. This parameter appears as a response when incorrect credentials are entered during login. The lack of proper validation or sanitization makes the component susceptible to injection attacks, potentially allowing attackers to manipulate the input and exploit the system.

CVSS3: 9.8
0%
Низкий
около 1 года назад

Уязвимостей на страницу