CVE-2024-47002

A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary html code. An authenticated user would need to click a malicious link provided by the attacker.
Configurations

Configuration 1 (hide)

cpe:2.3:a:observium:observium:24.4.13528:*:*:*:community:*:*:*

History

22 Aug 2025, 16:22

Type Values Removed Values Added
CPE cpe:2.3:a:observium:observium:24.4.13528:*:*:*:community:*:*:*
Summary
  • (es) Existe una vulnerabilidad de inyección de código HTML en la parte de administración de VLAN de Observium CE 24.4.13528. Una solicitud HTTP manipulada especialmente puede generar un código HTML arbitrario. Un usuario autenticado tendría que hacer clic en un enlace malicioso proporcionado por el atacante.
First Time Observium
Observium observium
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2091 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2091 - Exploit, Third Party Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2091 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2091 - Exploit, Third Party Advisory

15 Jan 2025, 17:15

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2091 -

15 Jan 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-15 15:15

Updated : 2025-08-22 16:22


NVD link : CVE-2024-47002

Mitre link : CVE-2024-47002

CVE.ORG link : CVE-2024-47002


JSON object : View

Products Affected

observium

  • observium
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')