CVE-2024-55199

A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.
Configurations

Configuration 1 (hide)

cpe:2.3:a:celk:celk_saude:3.1.252.1:*:*:*:*:*:*:*

History

23 Jun 2025, 20:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de tipo Cross Site Scripting (XSS) almacenado en Celk Sistemas Celk Saude v.3.1.252.1 permite a un atacante remoto almacenar código JavaScript dentro de un archivo PDF a través de la función de carga de archivos. Cuando se procesa el archivo, el código inyectado se ejecuta en el navegador del usuario.
First Time Celk celk Saude
Celk
CPE cpe:2.3:a:celk:celk_saude:3.1.252.1:*:*:*:*:*:*:*
References () https://github.com/gabriel-bri/vulnerability-research/tree/main/CVE-2024-55199 - () https://github.com/gabriel-bri/vulnerability-research/tree/main/CVE-2024-55199 - Exploit
References () https://portswigger.net/web-security/cross-site-scripting/stored - () https://portswigger.net/web-security/cross-site-scripting/stored - Technical Description

10 Mar 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-10 18:15

Updated : 2025-06-23 20:10


NVD link : CVE-2024-55199

Mitre link : CVE-2024-55199

CVE.ORG link : CVE-2024-55199


JSON object : View

Products Affected

celk

  • celk_saude
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')