Undergoing Analysis
CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Products
HyperView Geoportal Toolkit
- through 8.2.4
Source
cvd@cert.pl
Tags
CVE-2024-6449 details
Published : Aug. 28, 2024, 12:15 p.m.
Last Modified : Aug. 28, 2024, 12:57 p.m.
Last Modified : Aug. 28, 2024, 12:57 p.m.
Description
HyperView Geoportal Toolkit in versions though 8.2.4 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote attacker can prepare links, which upon opening will load scripts from a remote location controlled by the attacker and execute them in the user space. By manipulating this parameter it is also possible to enumerate some of the devices in Local Area Network in which the server resides.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-942 | Permissive Cross-domain Policy with Untrusted Domains | The product uses a cross-domain policy file that includes domains that should not be trusted. |
References
URL | Source |
---|---|
https://cert.pl/en/posts/2024/08/CVE-2024-6449 | cvd@cert.pl |
https://cert.pl/posts/2024/08/CVE-2024-6449 | cvd@cert.pl |
This website uses the NVD API, but is not approved or certified by it.