Description
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.
Published: 2024-04-26
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-1067 Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.
Github GHSA Github GHSA GHSA-2pg6-vw9c-qhjv Passbolt API allows HTML injection
History

No history.

Subscriptions

Passbolt Passbolt Api
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T02:36:04.533Z

Reserved: 2024-04-26T00:00:00.000Z

Link: CVE-2024-33670

cve-icon Vulnrichment

Updated: 2024-04-26T17:37:30.178Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-26T01:15:46.573

Modified: 2025-06-18T19:16:31.087

Link: CVE-2024-33670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses