PT-2024-23307 · Typebot · Typebot

Kwstubbs

·

Published

2024-04-04

·

Updated

2026-01-30

·

CVE-2024-30264

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Typebot versions prior to 2.24.0
Description A reflected cross-site scripting (XSS) issue in the sign-in page of typebot.io may allow an attacker to hijack a user's account. The sign-in page takes the redirectPath parameter from the URL. If a user clicks on a link where the redirectPath parameter has a javascript scheme, the attacker that crafted the link may be able to execute arbitrary JavaScript with the privileges of the user.
Recommendations For versions prior to 2.24.0, update to version 2.24.0 to resolve the issue. As a temporary workaround, consider restricting the use of the redirectPath parameter in the sign-in page to minimize the risk of exploitation. Avoid using the redirectPath parameter with a javascript scheme in the URL until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-30264
GHSA-MX2F-9MCR-8J73

Affected Products

Typebot