216.73.216.133

CVE-2024-6449

· Published 28/08/2024 12:15 · Modified 12/09/2024 15:32

Labels: CVE-2024-6449 2024-08-28CVE-2024-6449CWE-942NVD-CWE-Other[email protected]

Essential information

Published
28/08/2024 12:15
Modified
12/09/2024 15:32
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CVSS metrics

Description

HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote attacker can prepare links, which upon opening will load scripts from a remote location controlled by the attacker and execute them in the user space. By manipulating this parameter it is also possible to enumerate some of the devices in Local Area Network in which the server resides.

NVD status

Status
Analyzed — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
hyperview / geoportal toolkit cpe:2.3:a:hyperview:geoportal_toolkit:*:*:*:*:*:*:*:*

References