CVE-2024-48761

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 29, 2025
Updated: Feb 3, 2025
CWE ID 77

Summary

CVE-2024-48761 is a vulnerability affecting Celk Saude version 3.1.252.1. The issue lies in the component responsible for processing user input and returning error messages during login. This "erro" parameter, which is returned when incorrect login credentials are entered, is not adequately validated or sanitized. Consequently, this vulnerability exposes the system to injection attacks, enabling attackers to manipulate the input and potentially exploit the system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share