Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker to hijack a user's account. The sign-in page takes the `redirectPath` parameter from the URL. If a user clicks on a link where the `redirectPath` parameter has a javascript scheme, the attacker that crafted the link may be able to execute arbitrary JavaScript with the privileges of the user. Version 2.24.0 contains a patch for this issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-28187 Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker to hijack a user's account. The sign-in page takes the `redirectPath` parameter from the URL. If a user clicks on a link where the `redirectPath` parameter has a javascript scheme, the attacker that crafted the link may be able to execute arbitrary JavaScript with the privileges of the user. Version 2.24.0 contains a patch for this issue.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T01:32:06.369Z

Reserved: 2024-03-26T12:52:00.935Z

Link: CVE-2024-30264

cve-icon Vulnrichment

Updated: 2024-07-31T19:58:09.730Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-04T21:15:16.380

Modified: 2024-11-21T09:11:34.930

Link: CVE-2024-30264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses