CVE-2024-47531

MEDIUM

Scout - Info Disclosure

Title source: llm
STIX 2.1

Description

Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly downloading it and opening may lead to the compromise of users' devices or data. This vulnerability is fixed in 4.89.

Scores

CVSS v3 4.6
EPSS 0.0004
EPSS Percentile 12.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-116
Status published
Products (1)
clinical-genomics/scout < 4.89
Published Sep 30, 2024
Tracked Since Feb 18, 2026