PT-2025-10605 · Celk Sistemas · Celk Saude

Published

2025-03-10

·

Updated

2025-03-10

·

CVE-2024-55199

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Celk Sistemas Celk Saude version 3.1.252.1
Description A Stored Cross Site Scripting (XSS) issue allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.
Recommendations For Celk Sistemas Celk Saude version 3.1.252.1, consider disabling the file upload feature until a patch is available to prevent exploitation. Restrict access to uploaded files to minimize the risk of code execution.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-55199

Affected Products

Celk Saude