alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the preloaded data as json is not escaped correctly, the administrator / event admin could break their own install by inserting non correctly escaped text. The Content-Security-Policy directive blocks any potential script execution. The administrator or event administrator can override the texts for customization purpose. The texts are not properly escaped. Version 2.0-M5 fixes this issue.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Alf
Alf alf |
|
CPEs | cpe:2.3:a:alf:alf:*:*:*:*:*:*:*:* | |
Vendors & Products |
Alf
Alf alf |
|
Metrics |
ssvc
|
Fri, 06 Sep 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the preloaded data as json is not escaped correctly, the administrator / event admin could break their own install by inserting non correctly escaped text. The Content-Security-Policy directive blocks any potential script execution. The administrator or event administrator can override the texts for customization purpose. The texts are not properly escaped. Version 2.0-M5 fixes this issue. | |
Title | alf.io's preloaded data as json is not escaped correctly | |
Weaknesses | CWE-116 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-06T13:00:47.419Z
Updated: 2024-09-06T14:03:45.294Z
Reserved: 2024-08-26T18:25:35.443Z
Link: CVE-2024-45299
Vulnrichment
Updated: 2024-09-06T14:03:39.504Z
NVD
Status : Analyzed
Published: 2024-09-06T13:15:05.253
Modified: 2024-09-30T12:48:22.930
Link: CVE-2024-45299
Redhat
No data.