CVE-2024-48761: Celk Saude
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter.
Affected products
- Celk Celk Saude: version 3.1.252.1 only
Published 2025-01-29. Last modified 2026-06-17.