Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54492 | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file upload feature of the affected application improperly sanitizes xml files. This could allow an authenticated remote attacker to conduct a stored cross-site scripting attack by uploading specially crafted xml files that are later downloaded and viewed by other users of the application. |
Tue, 23 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens polarion Alm |
|
| CPEs | cpe:2.3:a:siemens:polarion_alm:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:polarion_alm:2310.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Siemens
Siemens polarion Alm |
Tue, 13 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The file upload feature of the affected application improperly sanitizes xml files. This could allow an authenticated remote attacker to conduct a stored cross-site scripting attack by uploading specially crafted xml files that are later downloaded and viewed by other users of the application. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2025-05-13T16:11:11.445Z
Reserved: 2024-10-28T07:01:23.767Z
Link: CVE-2024-51446
Updated: 2025-05-13T16:08:51.359Z
Status : Analyzed
Published: 2025-05-13T10:15:21.710
Modified: 2025-09-23T15:29:14.553
Link: CVE-2024-51446
No data.
OpenCVE Enrichment
No data.
EUVD