CVE Database
/

CVE-2024-33670

Back to search

CVE-2024-33670

Published: Apr 26, 2024

Modified: Aug 2, 2024

PUBLISHED

CVSS v3.1

4.3

MEDIUM

Description

Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.

VendorProductVersions

n/a

n/a

affected
n/a

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AC:L/AV:N/A:N/C:L/I:N/PR:N/S:U/UI:R

Attack Complexity

Low

Attack Vector

Network

Availability

None

Confidentiality

Low

Integrity

None

Privileges Required

None

Scope

Unchanged

User Interaction

Required

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now