PT-2024-40353 · Framework · Framework

Published

2024-05-23

·

Updated

2024-05-23

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Framework (affected versions not specified)
Description A low-level XSS issue has been found in the Framework, affecting HTTP redirection via the Director::force redirect method. This issue occurs when attempts to redirect to a URL may generate HTML that is not safely escaped, posing a risk of XSS in some environments. The difficulty of exploitation is noted as low because any injected HTML will only be returned from the server if the Location HTTP header is also sent, meaning user exposure is limited as browsers redirect before displaying the response body.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-JQP8-V74P-G8PX

Affected Products

Framework