PT-2023-21151 · Directus · Directus
Tofra
·
Published
2023-03-06
·
Updated
2023-03-13
·
CVE-2023-27474
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Directus versions prior to 9.23.0
Description
Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset URL are vulnerable to an HTML injection attack through the use of query parameters in the reset URL. An attacker could exploit this to email users URLs to the server's domain but which may contain malicious code.
Recommendations
For versions prior to 9.23.0, upgrade to 9.23.0 or later.
Alternatively, remove the custom reset URL from the configured allow list.
As a temporary workaround, consider disabling the custom reset URL allow list until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Directus