PT-2024-36800 · Unknown · Grist-Core

Vviers

·

Published

2024-12-20

·

Updated

2024-12-20

·

CVE-2024-56358

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions grist-core versions prior to 1.3.2
Description The issue concerns a spreadsheet hosting server where a user's account could be compromised by visiting a malicious document and previewing an attachment. This happens because JavaScript in an SVG file is evaluated in the context of the user's current page, allowing for potential account takeover.
Recommendations For versions prior to 1.3.2, upgrade to version 1.3.2 or later to resolve the issue. As a temporary workaround for users unable to upgrade, avoid previewing attachments in documents prepared by untrusted individuals.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-56358
GHSA-JVFM-GF4F-33Q3

Affected Products

Grist-Core