Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-30264

Опубликовано: 04 апр. 2024
Источник: nvd
CVSS3: 8.1
CVSS3: 9.3
EPSS Низкий

Описание

Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker to hijack a user's account. The sign-in page takes the redirectPath parameter from the URL. If a user clicks on a link where the redirectPath parameter has a javascript scheme, the attacker that crafted the link may be able to execute arbitrary JavaScript with the privileges of the user. Version 2.24.0 contains a patch for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:typebot:typebot:*:*:*:*:*:-:*:*
Версия до 2.24.0 (исключая)

EPSS

Процентиль: 73%
0.00771
Низкий

8.1 High

CVSS3

9.3 Critical

CVSS3

Дефекты

CWE-79

EPSS

Процентиль: 73%
0.00771
Низкий

8.1 High

CVSS3

9.3 Critical

CVSS3

Дефекты

CWE-79