PT-2024-25428 · Passbolt · Passbolt Api

Ruben Meeuwissen

·

Published

2024-04-26

·

Updated

2025-06-18

·

CVE-2024-33670

CVSS v3.1

4.3

Medium

VectorAC:L/AV:N/A:N/C:L/I:N/PR:N/S:U/UI:R
Name of the Vulnerable Software and Affected Versions Passbolt API versions prior to 4.6.2
Description The issue allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.
Recommendations For Passbolt API versions prior to 4.6.2, update to version 4.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to URL parameters to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-33670
GHSA-2PG6-VW9C-QHJV

Affected Products

Passbolt Api