Critical severity9.0NVD Advisory· Published Feb 6, 2025· Updated Jun 17, 2026
CVE-2024-39272
CVE-2024-39272
Description
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arbitrary html code. An attacker can send a series of HTTP requests to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:clear:clearml_enterprise_server:3.22.5-1533:*:*:*:*:*:*:*
- Range: = 3.22.5-1533
Patches
Vulnerability mechanics
References
2- talosintelligence.com/vulnerability_reports/TALOS-2024-2110nvdThird Party Advisory
- www.talosintelligence.com/vulnerability_reports/TALOS-2024-2110nvdThird Party Advisory
News mentions
0No linked articles in our index yet.