Vulnerability Description
HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote attacker can prepare links, which upon opening will load scripts from a remote location controlled by the attacker and execute them in the user space. By manipulating this parameter it is also possible to enumerate some of the devices in Local Area Network in which the server resides.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hyperview | Geoportal Toolkit | <= 8.5.0 |
Related Weaknesses (CWE)
References
- https://cert.pl/en/posts/2024/08/CVE-2024-6449Third Party Advisory
- https://cert.pl/posts/2024/08/CVE-2024-6449Third Party Advisory
FAQ
What is CVE-2024-6449?
CVE-2024-6449 is a vulnerability with a CVSS score of 6.5 (MEDIUM). HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote attack...
How severe is CVE-2024-6449?
CVE-2024-6449 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6449?
Check the references section above for vendor advisories and patch information. Affected products include: Hyperview Geoportal Toolkit.