Description
Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0631 | Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS) |
Github GHSA |
GHSA-fqxj-46wg-9v84 | Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS) |
References
History
Tue, 01 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dpgaspar
Dpgaspar flask-appbuilder |
|
| CPEs | cpe:2.3:a:dpgaspar:flask-appbuilder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dpgaspar
Dpgaspar flask-appbuilder |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-08T19:24:18.993Z
Reserved: 2024-02-19T14:43:05.991Z
Link: CVE-2024-27083
Updated: 2024-08-02T00:27:57.821Z
Status : Analyzed
Published: 2024-02-29T01:44:19.387
Modified: 2025-04-01T15:22:28.893
Link: CVE-2024-27083
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA