PT-2024-21643 · Unknown · Hoppscotch
Mbiesiad
·
Published
2024-02-26
·
Updated
2025-04-01
·
CVE-2024-27092
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Hoppscotch versions prior to 2023.12.6
Description
Hoppscotch is an API development ecosystem. Due to the lack of validation for fields like
Label (Edit Team) - TeamName, bad actors can send emails with spoofed content as Hoppscotch. Part of the payload, an external link, is presented in a clickable form, making it easier for malicious actors to achieve their goals.Recommendations
For versions prior to 2023.12.6, update to version 2023.12.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the
Label (Edit Team) - TeamName field to minimize the risk of exploitation. Avoid using external links in the payload until the issue is resolved.Exploit
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hoppscotch