Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Riyush Ghimire

#44023of 53,633
6.1Total CVSS
Vulnerabilities · 1
PT-2024-21798
6.1
2024-02-29
Unknown · Docassemble · CVE-2024-27290
**Name of the Vulnerable Software and Affected Versions** Docassemble versions prior to 1.4.97 **Description** The issue allows a user to type HTML into a field, including the field for the user's name, and then that HTML could be displayed on the screen as HTML. The HTML can also contain `<script>` tags, allowing JavaScript to execute on the page. **Recommendations** For versions prior to 1.4.97, update to version 1.4.97 of the master branch to resolve the issue. If upgrading is not possible, manually apply the changes of the specified commit and restart the server.