CVE-2024-55199: Celk Saude

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.

Affected products

  • Celk Celk Saude: version 3.1.252.1 only

Published 2025-03-10. Last modified 2026-06-17.