PT-2024-36799 · Unknown · Grist-Core

Spawnzii

+1

·

Published

2024-12-20

·

Updated

2024-12-20

·

CVE-2024-56357

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions grist-core versions prior to 1.3.1
Description A user visiting a malicious document or submitting a malicious form could have their account compromised due to the ability to use the javascript: scheme with custom widget URLs and form redirect URLs.
Recommendations For versions prior to 1.3.1, upgrade to version 1.3.1 to resolve the issue. As a temporary workaround for users unable to upgrade, avoid visiting documents or forms prepared by people they do not trust.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-56357
GHSA-CQ5Q-CQR7-VMF6

Affected Products

Grist-Core