CVE-2024-6449
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/08/2024
Last modified:
12/09/2024
Description
HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters.<br />
An unauthenticated remote attacker can prepare links, which upon opening will load scripts from a remote location controlled by the attacker and execute them in the user space.<br />
By manipulating this parameter it is also possible to enumerate some of the devices in Local Area Network in which the server resides.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:hyperview:geoportal_toolkit:*:*:*:*:*:*:*:* | 8.5.0 (including) |
To consult the complete list of CPE names with products and versions, see this page