PT-2024-26897 · Unknown · Ansibleguy-Webui

Ntrampham

·

Published

2024-05-28

·

Updated

2024-05-29

·

CVE-2024-36110

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions ansibleguy-webui versions prior to 0.0.21
Description The issue allows injection of HTML elements in multiple forms, which are then evaluated by the browser after job actions are executed. This can lead to potential security risks. There are no known workarounds for these issues.
Recommendations For versions prior to 0.0.21, upgrade to version 0.0.21 or later to resolve the issue. As a temporary workaround, consider restricting the use of the affected forms until a patch is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-36110
GHSA-927P-XRC2-X2GJ

Affected Products

Ansibleguy-Webui