CVE-2024-55199

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 10, 2025
CWE ID 79

Summary

CVE-2024-55199 is a newly discovered Stored Cross-Site Scripting (XSS) vulnerability affecting Celk Sistemas Celk Saude version 3.1.252.1. An attacker can exploit this weakness by inserting malicious JavaScript code into a PDF file via the file upload feature. Once the file is rendered, the injected code is executed on the user's browser, potentially leading to data theft, unauthorized access, or other malicious activities. This vulnerability poses a significant risk to organizations and users who utilize the Celk Sistemas Celk Saude software for handling sensitive data. It is crucial to apply the necessary patches or updates as soon as they become available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share