SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-6533

Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client.

MEDIUM 5.4EPSS 0.38%

Does this matter?

Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.

Description

Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that will be stored in the server and used by the client into an unsanitized DOM element. When chained with CVE-2024-6534, it could result in account takeover.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.38% probability · 31th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
monospace/directus
Source
help@fluidattacks.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.