CVE-2024-6449
MEDIUMDescription
HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote attacker can prepare links, which upon opening will load scripts from a remote location controlled by the attacker and execute them in the user space. By manipulating this parameter it is also possible to enumerate some of the devices in Local Area Network in which the server resides.
Is your site exposed to CVE-2024-6449?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| hyperview | geoportal_toolkit |
References
Frequently Asked Questions
What is CVE-2024-6449? +
How severe is CVE-2024-6449? +
What products are affected by CVE-2024-6449? +
How do I check if I'm vulnerable to CVE-2024-6449? +
Related Vulnerabilities
PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensitive information from PlexRipper …
Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, an open CORS …
claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due to improper …
Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to …
Rob -- W / cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to …
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to …