Celk Sistemas Celk Saude Stored Cross-Site Scripting Vulnerability via File Upload
Vulnerability
A stored cross-site scripting vulnerability has been identified in Celk Sistemas Celk Saude version 3.1.252.1. This vulnerability allows remote attackers to inject JavaScript into PDF files through the application's file upload feature. Once the PDF is opened, the embedded script executes in the user's browser.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user's session with the application.
Reproduction
To reproduce this vulnerability, upload a PDF file containing JavaScript code, such as a script that triggers an alert, using the application's file upload feature. After the file is uploaded, it can be accessed and will execute the embedded JavaScript when opened, demonstrating the cross-site scripting vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
