PT-2024-31552 · Alf.Io · Alf.Io

Cbellone

·

Published

2024-09-06

·

Updated

2024-09-30

·

CVE-2024-45299

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions alf.io versions prior to 2.0-M5
Description The issue concerns an open source ticket reservation system for events. Prior to version 2.0-M5, the preloaded data as JSON is not escaped correctly. This allows an administrator or event admin to potentially break their own installation by inserting non-correctly escaped text. However, the Content-Security-Policy directive blocks any potential script execution. The texts for customization purposes are not properly escaped.
Recommendations For versions prior to 2.0-M5, update to version 2.0-M5 to resolve the issue. As a temporary workaround, consider avoiding the use of non-escaped text in customization to minimize the risk of installation breakage.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2024-45299
GHSA-MCX6-25F8-8RQW

Affected Products

Alf.Io