cve/2024/CVE-2024-55199.md
2025-09-29 16:08:36 +00:00

757 B

CVE-2024-55199

Description

A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.

POC

Reference

Github

No PoCs found on GitHub currently.