VDB
CVE-2024-51446
CVE-2024-51446
PUBLISHED
CVSS 6.5 MEDIUM
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file upload feature of the affected application improperly sanitizes xml files. This could allow an authenticated remote attacker to conduct a stored cross-site scripting attack by uploading specially crafted xml files that are later downloaded and viewed by other users of the application.
EPSS 0.32% · 23.0th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
EPSS Score
0.32%
23.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Polarion V2310 | 0 |
| Siemens | Polarion V2404 | 0 |
| siemens | polarion_alm | 2404.0, 2310.0 |
Timeline
- May 13, 2025 EPSS Score
- May 13, 2025 Coalition ESS Score
- May 13, 2025 CVE Published
- May 13, 2025 CVE Updated
- May 15, 2025 PoC Published
- May 25, 2025 EPSS Score
- Jun 6, 2025 EPSS Score
- Jun 18, 2025 EPSS Score
- Jun 30, 2025 EPSS Score
- Jul 11, 2025 EPSS Score
- Jul 23, 2025 EPSS Score
- Aug 4, 2025 EPSS Score