Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a color column or entry is rendered. Filament v3.2.115 fixes this issue.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00055}

epss

{'score': 0.0006}


Mon, 07 Oct 2024 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Filamentphp
Filamentphp filament
CPEs cpe:2.3:a:filamentphp:filament:*:*:*:*:*:*:*:*
Vendors & Products Filamentphp
Filamentphp filament

Fri, 27 Sep 2024 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Sep 2024 21:15:00 +0000

Type Values Removed Values Added
Description Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a color column or entry is rendered. Filament v3.2.115 fixes this issue.
Title Filament has unvalidated ColorColumn and ColorEntry values that can be used for Cross-site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-27T21:56:30.280Z

Reserved: 2024-09-19T22:32:11.963Z

Link: CVE-2024-47186

cve-icon Vulnrichment

Updated: 2024-09-27T21:49:15.814Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-27T21:15:03.443

Modified: 2024-10-07T13:30:55.640

Link: CVE-2024-47186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.