PT-2024-21643 · Unknown · Hoppscotch

Mbiesiad

·

Published

2024-02-26

·

Updated

2025-04-01

·

CVE-2024-27092

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hoppscotch versions prior to 2023.12.6
Description Hoppscotch is an API development ecosystem. Due to the lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with spoofed content as Hoppscotch. Part of the payload, an external link, is presented in a clickable form, making it easier for malicious actors to achieve their goals.
Recommendations For versions prior to 2023.12.6, update to version 2023.12.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the Label (Edit Team) - TeamName field to minimize the risk of exploitation. Avoid using external links in the payload until the issue is resolved.

Exploit

Fix

XSS

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-27092
GHSA-8R6H-8R68-Q3PP

Affected Products

Hoppscotch