CVE-2024-45061

A cross-site scripting (xss) vulnerability exists in the weather map editor functionality of Observium CE 24.4.13528. A specially crafted HTTP request can lead to a arbitrary javascript code execution. An authenticated user would need to click a malicious link provided by the attacker.
Configurations

Configuration 1 (hide)

cpe:2.3:a:observium:observium:24.4.13528:*:*:*:community:*:*:*

History

22 Aug 2025, 16:25

Type Values Removed Values Added
CPE cpe:2.3:a:observium:observium:24.4.13528:*:*:*:community:*:*:*
Summary
  • (es) Existe una vulnerabilidad de cross-site scripting (XSS) en la función de edición de mapas meteorológicos de Observium CE 24.4.13528. Una solicitud HTTP manipulada especialmente puede provocar la ejecución de un código JavaScript arbitrario. Un usuario autenticado tendría que hacer clic en un enlace malicioso proporcionado por el atacante.
First Time Observium
Observium observium
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2092 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2092 - Exploit, Third Party Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2092 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2092 - Exploit, Third Party Advisory

15 Jan 2025, 17:15

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2092 -

15 Jan 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-15 15:15

Updated : 2025-08-22 16:25


NVD link : CVE-2024-45061

Mitre link : CVE-2024-45061

CVE.ORG link : CVE-2024-45061


JSON object : View

Products Affected

observium

  • observium
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')