PT-2024-37636 · Unknown · Hyperview Geoportal Toolkit
Dariusz Goåda
+1
·
Published
2024-08-28
·
Updated
2024-09-12
·
CVE-2024-6449
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HyperView Geoportal Toolkit versions prior to 8.5.0
Description
The issue allows an unauthenticated remote attacker to prepare links that, when opened, will load scripts from a remote location controlled by the attacker and execute them in the user space. By manipulating a
GET request parameter, it is also possible to enumerate some of the devices in the Local Area Network in which the server resides.Recommendations
For versions prior to 8.5.0, update to a patched version as soon as possible and review access controls to mitigate the risk of unauthorized access. As a temporary workaround, consider restricting access to the vulnerable
GET request parameter until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hyperview Geoportal Toolkit