CVE-2024-47002 Details
Description
A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary html code. An authenticated user would need to click a malicious link provided by the attacker.
A HTML code injection vulnerability has been identified in the VLAN management section of Observium Community Edition (CE) version 24.4.13528. This vulnerability allows an authenticated user to inject arbitrary HTML code by clicking on a malicious link. The injection is achieved through a specially crafted HTTP request that exploits the VLAN functionality by manipulating the 'vlan_id' parameter.
Users are advised to update to the latest version of Observium CE, as the vulnerability has been patched in the most recent release.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2091 | CVE | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2024-2091 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| observium observium | 24.4.13528 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 22, 2025 | Initial Analysis | [email protected] |
| Jan 15, 2025 | CVE Modified | CVE |
| Jan 15, 2025 | New CVE Received | [email protected] |