VYPR
Unrated severityNVD Advisory· Published Jan 15, 2025· Updated Jan 15, 2025

CVE-2024-47002

CVE-2024-47002

Description

A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary html code. An authenticated user would need to click a malicious link provided by the attacker.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A reflected cross-site scripting vulnerability in Observium CE 24.4.13528 allows authenticated users to inject arbitrary HTML via the vlan_id parameter.

Vulnerability

A reflected HTML injection vulnerability exists in the VLAN management page of Observium CE version 24.4.13528. The vlan_id parameter is not properly sanitized before being reflected in the response, allowing an attacker to inject arbitrary HTML code. The vulnerability is classified as CWE-79 (Cross-site Scripting). [1]

Exploitation

An attacker must craft a malicious URL containing a specially crafted vlan_id parameter, such as `. The victim must be authenticated to Observium and click the link. No additional privileges are required beyond standard user authentication. The advisory demonstrates a reflected XSS via a GET request to /vlan/?vlan_id=...`. [1]

Impact

Successful exploitation allows the attacker to inject arbitrary HTML into the victim's browser session, potentially leading to data theft, session hijacking, or defacement. The CVSSv3 score is 8.7 (High) with confidentiality and integrity impacts rated as High, and scope changed. No impact on availability. [1]

Mitigation

As of the publication date, no official patch or workaround has been disclosed in the available references. Users should monitor the Observium project for updates and consider restricting access to the VLAN management page until a fix is released. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Observium/Observium CEllm-create2 versions
    = 24.4.13528+ 1 more
    • (no CPE)range: = 24.4.13528
    • (no CPE)range: CE 24.4.13528

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.