The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13051 | Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices. |
Wed, 01 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:* |
Thu, 01 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 May 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices. | |
| Title | Kibana Unrestricted Upload of File with Dangerous Type Can Lead to XSS | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2025-05-01T13:26:43.673Z
Reserved: 2024-11-18T22:26:31.910Z
Link: CVE-2024-11390
Updated: 2025-05-01T13:26:39.944Z
Status : Analyzed
Published: 2025-05-01T14:15:34.913
Modified: 2025-10-01T19:29:57.070
Link: CVE-2024-11390
No data.
OpenCVE Enrichment
Updated: 2025-07-12T23:05:43Z
EUVD