Логотип exploitDog
bind:CVE-2024-22191
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-22191

Количество 2

Количество 2

nvd логотип

CVE-2024-22191

около 2 лет назад

Avo is a framework to create admin panels for Ruby on Rails apps. A stored cross-site scripting (XSS) vulnerability was found in the key_value field of Avo v3.2.3 and v2.46.0. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the victim's browser. The value of the key_value is inserted directly into the HTML code. In the current version of Avo (possibly also older versions), the value is not properly sanitized before it is inserted into the HTML code. This vulnerability could be used to steal sensitive information from victims that could be used to hijack victims' accounts or redirect them to malicious websites. Avo 3.2.4 and 2.47.0 include a fix for this issue. Users are advised to upgrade.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-ghjv-mh6x-7q6h

около 2 лет назад

avo vulnerable to stored cross-site scripting (XSS) in key_value field

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-22191

Avo is a framework to create admin panels for Ruby on Rails apps. A stored cross-site scripting (XSS) vulnerability was found in the key_value field of Avo v3.2.3 and v2.46.0. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the victim's browser. The value of the key_value is inserted directly into the HTML code. In the current version of Avo (possibly also older versions), the value is not properly sanitized before it is inserted into the HTML code. This vulnerability could be used to steal sensitive information from victims that could be used to hijack victims' accounts or redirect them to malicious websites. Avo 3.2.4 and 2.47.0 include a fix for this issue. Users are advised to upgrade.

CVSS3: 7.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-ghjv-mh6x-7q6h

avo vulnerable to stored cross-site scripting (XSS) in key_value field

CVSS3: 7.3
1%
Низкий
около 2 лет назад

Уязвимостей на страницу