VulnerabilityAnalyzed
CVE-2024-33670
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL.
MEDIUM 4.3EPSS 0.48%
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- passbolt/passbolt api
- Source
- cve@mitre.org
References
- https://help.passbolt.com/incidents/reflective-html-injection-vulnerabilityIssue Tracking, Vendor Advisory
- https://www.passbolt.com/incidentsIssue Tracking, Vendor Advisory
- https://www.passbolt.com/security/moreProduct
- https://help.passbolt.com/incidents/reflective-html-injection-vulnerabilityIssue Tracking, Vendor Advisory
- https://www.passbolt.com/incidentsIssue Tracking, Vendor Advisory
- https://www.passbolt.com/security/moreProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.