PT-2025-18389 · Elastic · Kibana
Published
2025-05-01
·
Updated
2025-05-05
·
CVE-2024-11390
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Kibana (affected versions not specified)
Description
The issue allows for the unrestricted upload of files with dangerous types, potentially leading to arbitrary JavaScript execution in a victim's browser, resulting in a cross-site scripting (XSS) attack. This can be achieved via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app and/or have write access to the synthetics indices.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kibana