← Vulnerability feed

Vulnerability record · CVE-2024-47002 · published 15 January 2025

CVE-2024-47002: Observium cross-site scripting vulnerability

Observium · Observium

A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary html code. An authenticated user would need to click a malicious link provided by the attacker.

5.4 CVSS 3.1 Medium EPSS 15% · top 3.3% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary html code. An authenticated user would need to click a malicious link provided by the attacker.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-47002 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-25147Observium sql injection vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is po…EPSS 1.4%9.8CVE-2020-25132Observium sql injection vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is po…EPSS 1.6%8.8CVE-2020-25143Observium sql injection vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is po…EPSS 1.2%8.8CVE-2020-25144Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.2%8.8CVE-2020-25145Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.2%8.8CVE-2020-25149Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.2%8.8CVE-2020-25136Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.0%8.8CVE-2020-25134Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2024-47002), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.