PT-2024-36800 · Unknown · Grist-Core
Vviers
·
Published
2024-12-20
·
Updated
2024-12-20
·
CVE-2024-56358
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
grist-core versions prior to 1.3.2
Description
The issue concerns a spreadsheet hosting server where a user's account could be compromised by visiting a malicious document and previewing an attachment. This happens because JavaScript in an SVG file is evaluated in the context of the user's current page, allowing for potential account takeover.
Recommendations
For versions prior to 1.3.2, upgrade to version 1.3.2 or later to resolve the issue.
As a temporary workaround for users unable to upgrade, avoid previewing attachments in documents prepared by untrusted individuals.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grist-Core