Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-04-26T00:00:00

Updated: 2024-08-02T02:36:04.533Z

Reserved: 2024-04-26T00:00:00

Link: CVE-2024-33670

cve-icon Vulnrichment

Updated: 2024-04-26T17:37:30.178Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-26T01:15:46.573

Modified: 2024-11-21T09:17:22.573

Link: CVE-2024-33670

cve-icon Redhat

No data.