CVE-2024-55199 Details
Description
A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.
A stored cross-site scripting vulnerability has been identified in Celk Sistemas Celk Saude version 3.1.252.1. This vulnerability allows remote attackers to inject JavaScript into PDF files through the application's file upload feature. Once the PDF is opened, the embedded script executes in the user's browser.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gabriel-bri/vulnerability-research/tree/main/CVE-2024-55199 | CISA-ADP | Exploit |
| https://github.com/gabriel-bri/vulnerability-research/tree/main/CVE-2024-55199 | [email protected] | Exploit |
| https://portswigger.net/web-security/cross-site-scripting/stored | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| celk celk saude | 3.1.252.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2025 | Initial Analysis | [email protected] |
| Mar 10, 2025 | New CVE Received | [email protected] |
| Mar 10, 2025 | CVE Modified | CISA-ADP |