CVE-2024-47140

A cross-site scripting (xss) vulnerability exists in the add_alert_check page of Observium CE 24.4.13528. A specially crafted HTTP request can lead to a arbitrary javascript code execution. An authenticated user would need to click a malicious link provided by the attacker.
Configurations

Configuration 1 (hide)

cpe:2.3:a:observium:observium:24.4.13528:*:*:*:community:*:*:*

History

22 Aug 2025, 16:19

Type Values Removed Values Added
CPE cpe:2.3:a:observium:observium:24.4.13528:*:*:*:community:*:*:*
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2090 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-2090 - Exploit, Third Party Advisory
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2090 - () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2090 - Exploit, Third Party Advisory
Summary
  • (es) Existe una vulnerabilidad de cross-site scripting (XSS) en la página add_alert_check de Observium CE 24.4.13528. Una solicitud HTTP manipulada especialmente puede provocar la ejecución de un código JavaScript arbitrario. Un usuario autenticado tendría que hacer clic en un enlace malicioso proporcionado por el atacante.
First Time Observium
Observium observium

15 Jan 2025, 17:15

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2090 -

15 Jan 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-15 15:15

Updated : 2025-08-22 16:19


NVD link : CVE-2024-47140

Mitre link : CVE-2024-47140

CVE.ORG link : CVE-2024-47140


JSON object : View

Products Affected

observium

  • observium
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')