CVE-2024-6449

Aug. 28, 2024, 12:57 p.m.

Undergoing Analysis
CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

Products

HyperView Geoportal Toolkit

  • through 8.2.4

Source

cvd@cert.pl

Tags

CVE-2024-6449 details

Published : Aug. 28, 2024, 12:15 p.m.
Last Modified : Aug. 28, 2024, 12:57 p.m.

Description

HyperView Geoportal Toolkit in versions though 8.2.4 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote attacker can prepare links, which upon opening will load scripts from a remote location controlled by the attacker and execute them in the user space. By manipulating this parameter it is also possible to enumerate some of the devices in Local Area Network in which the server resides.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-942 Permissive Cross-domain Policy with Untrusted Domains The product uses a cross-domain policy file that includes domains that should not be trusted.
This website uses the NVD API, but is not approved or certified by it.