PT-2024-4535 · Querybook · Querybook

Hakupiku

·

Published

2024-02-21

·

Updated

2025-02-05

·

CVE-2024-26148

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Querybook versions prior to 3.31.1
Description: The issue is related to the Rich Text Editor component in Querybook, which fails to properly validate user input, allowing arbitrary URLs to be entered without necessary validation. This security flaw enables the use of the javascript: protocol, potentially triggering arbitrary client-side execution. In the most extreme case, an admin user could unknowingly click on a cross-site scripting URL, compromising admin role access to the attacker.
Recommendations: For versions prior to 3.31.1, update to version 3.31.1 or later, as it includes a patch to rectify this issue. The fix is backward compatible and automatically fixes existing DataDocs. As a temporary workaround, consider manually checking each URL prior to clicking on them to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-05039
CVE-2024-26148
GHSA-FH6G-GVVP-587F

Affected Products

Querybook