CVE-2024-51446 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file upload feature of the affected applicati…
Medium CVSS: 5.1

CVE-2024-51446

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file upload feature of the affected application improperly sanitizes xml files. This could allow an authenticated remote attacker to conduct a stored cross-site scripting attack by uploading specially crafted xml files that are later downloaded and viewed by other users of the application.
Vendor
Siemens
Product
Polarion Alm
CWE
CWE-79
Yayın Tarihi
2025-05-13 10:15:21
Güncelleme
2025-09-23 15:29:14
Source Identifier
productcert@siemens.com
KEV Date Added
-

Kategoriler

Referanslar