← volver
CVE-2024-11390mediumCWE-434

Kibana Unrestricted Upload of File with Dangerous Type Can Lead to XSS

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 5.4epss 0.3%
probabilidad de explotación
0.3%top 74% de las CVE
explotación observada
noninguna fuente lo reporta
Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Productos afectados
Elastic · Kibana