PT-2022-16938 · Unknown · Origin Protocol

Jorgectf

+1

·

Published

2022-04-20

·

Updated

2022-04-28

·

CVE-2022-24864

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Origin Protocol (affected versions not specified)
Description The Origin Protocol project website is susceptible to malicious Javascript injection via a POST request to "/presale/join". User-controlled data is passed without sanitization to SendGrid and injected into an email delivered to the founders@originprotocol.com. If the email recipient's program is vulnerable to XSS, they may receive an email with malicious XSS. Regardless, the hacker can inject malicious HTML that modifies the email's body content.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24864
GHSA-V6FC-QWXX-M4H7

Affected Products

Origin Protocol