Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22191

Опубликовано: 16 янв. 2024
Источник: nvd
CVSS3: 7.3
CVSS3: 5.4
EPSS Низкий

Описание

Avo is a framework to create admin panels for Ruby on Rails apps. A stored cross-site scripting (XSS) vulnerability was found in the key_value field of Avo v3.2.3 and v2.46.0. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the victim's browser. The value of the key_value is inserted directly into the HTML code. In the current version of Avo (possibly also older versions), the value is not properly sanitized before it is inserted into the HTML code. This vulnerability could be used to steal sensitive information from victims that could be used to hijack victims' accounts or redirect them to malicious websites. Avo 3.2.4 and 2.47.0 include a fix for this issue. Users are advised to upgrade.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:avohq:avo:*:*:*:*:*:ruby:*:*
Версия до 2.47.0 (исключая)
cpe:2.3:a:avohq:avo:*:*:*:*:*:ruby:*:*
Версия от 3.0.0 (включая) до 3.3.0 (исключая)

EPSS

Процентиль: 79%
0.01253
Низкий

7.3 High

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.3
github
около 2 лет назад

avo vulnerable to stored cross-site scripting (XSS) in key_value field

EPSS

Процентиль: 79%
0.01253
Низкий

7.3 High

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79