PT-2024-28738 · Unknown · Vaultwarden
Mirko Richter
+1
·
Published
2024-09-13
·
Updated
2025-07-10
·
CVE-2024-39926
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Vaultwarden (formerly Bitwarden RS) version 1.30.3
Description
A stored cross-site scripting (XSS) or HTML injection issue has been discovered in the admin dashboard. This potentially allows an authenticated attacker to inject malicious code into the dashboard, which is then executed or rendered in the context of an administrator's browser when viewing the injected content. The default Content Security Policy (CSP) of the application blocks most exploitation paths, significantly mitigating the potential impact.
Recommendations
For version 1.30.3, consider disabling access to the admin dashboard until a patch is available to prevent potential exploitation. Restrict the use of the vulnerable component in the admin dashboard to minimize the risk of malicious code injection.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vaultwarden