Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-26148

Опубликовано: 21 фев. 2024
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Querybook is a user interface for querying big data. Prior to version 3.31.1, there is a vulnerability in Querybook's rich text editor that enables users to input arbitrary URLs without undergoing necessary validation. This particular security flaw allows the use of javascript: protocol which can potentially trigger arbitrary client-side execution. The most extreme exploit of this flaw could occur when an admin user unknowingly clicks on a cross-site scripting URL, thereby unintentionally compromising admin role access to the attacker. A patch to rectify this issue has been introduced in Querybook version 3.31.1. The fix is backward compatible and automatically fixes existing DataDocs. There are no known workarounds for this issue, except for manually checking each URL prior to clicking on them.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pinterest:querybook:*:*:*:*:*:*:*:*
Версия до 3.31.1 (исключая)

EPSS

Процентиль: 54%
0.00317
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.1
fstec
почти 2 года назад

Уязвимость компонента Rich Text Editor среды обработки больших данных Querybook, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 54%
0.00317
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79