Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-26152

Опубликовано: 22 фев. 2024
Источник: nvd
CVSS3: 4.7
CVSS3: 6.1
EPSS Низкий

Описание

Summary

On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a Choices or Labels tag, resulting in an XSS vulnerability.

Details

Need permission to use the "data import" function. This was reproduced on Label Studio 1.10.1.

PoC

  1. Create a project. Create a project

  2. Upload a file containing the payload using the "Upload Files" function. 2  Upload a file containing the payload using the Upload Files function 3  complete

The following are the contents of the files used in the PoC

{ "data": { "prompt": "

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:humansignal:label_studio:*:*:*:*:*:*:*:*
Версия до 1.11.0 (исключая)

EPSS

Процентиль: 80%
0.01335
Низкий

4.7 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 4.7
debian
почти 2 года назад

### Summary On all Label Studio versions prior to 1.11.0, data importe ...

CVSS3: 4.7
github
почти 2 года назад

Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config

EPSS

Процентиль: 80%
0.01335
Низкий

4.7 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79