PT-2024-31552 · Alf.Io · Alf.Io
Cbellone
·
Published
2024-09-06
·
Updated
2024-09-30
·
CVE-2024-45299
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
alf.io versions prior to 2.0-M5
Description
The issue concerns an open source ticket reservation system for events. Prior to version 2.0-M5, the preloaded data as JSON is not escaped correctly. This allows an administrator or event admin to potentially break their own installation by inserting non-correctly escaped text. However, the Content-Security-Policy directive blocks any potential script execution. The texts for customization purposes are not properly escaped.
Recommendations
For versions prior to 2.0-M5, update to version 2.0-M5 to resolve the issue. As a temporary workaround, consider avoiding the use of non-escaped text in customization to minimize the risk of installation breakage.
Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alf.Io