PT-2024-27350 · Ghtml · Ghtml

Lirantal

·

Published

2024-06-10

·

Updated

2024-06-11

·

CVE-2024-37166

CVSS v3.1

8.9

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions ghtml versions prior to 2.0.0
Description The issue allows for the introduction of user-controlled JavaScript code, potentially triggering a Cross-Site Scripting (XSS) vulnerability in certain cases. Developers should be cautious and take additional measures to sanitize user input and prevent potential vulnerabilities. The backtick character (`) is now also escaped to prevent the creation of strings in most cases where a malicious actor gains the ability to write JavaScript. However, this does not provide comprehensive protection against all types of XSS attacks.
Recommendations For versions prior to 2.0.0, update to version 2.0.0 to address the Cross-Site Scripting vulnerabilities. Additionally, consider implementing extra sanitization measures for user input to enhance cybersecurity. As a temporary workaround, consider restricting the use of user-controlled input in template engine functionality until the issue is fully resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-37166
GHSA-VVHJ-V88F-5GXR

Affected Products

Ghtml