PT-2024-21350 · Serenity · Serenity
Published
2024-02-18
·
Updated
2025-03-25
·
CVE-2024-26318
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Serenity versions prior to 6.8.0
Description
The issue allows for XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / character. This is due to a flaw in the
LoginPage.tsx file.Recommendations
For versions prior to 6.8.0, update to version 6.8.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of return URLs in
LoginPage.tsx to only those that begin with a / character.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Serenity