CVE-2024-55198
- EPSS 0.13%
- Veröffentlicht 13.03.2025 15:15:49
- Zuletzt bearbeitet 03.04.2025 18:31:39
User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users through discrepancies in the responses.
CVE-2024-55199
- EPSS 0.04%
- Veröffentlicht 10.03.2025 00:00:00
- Zuletzt bearbeitet 23.06.2025 20:10:31
A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on...
CVE-2024-48761
- EPSS 0.39%
- Veröffentlicht 29.01.2025 22:15:29
- Zuletzt bearbeitet 23.05.2025 15:26:18
Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter.
CVE-2024-51182
- EPSS 0.09%
- Veröffentlicht 29.01.2025 22:15:29
- Zuletzt bearbeitet 23.05.2025 15:25:17
HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary HTML code via the "erro" parameter.