CVE-2024-22414

CVSS V2 None CVSS V3 None
Description
flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitrary javascript code. The html template `user.html` contains the following code snippet to render comments made by a user: `<div class="content" tag="content">{{comment[2]|safe}}</div>`. Use of the "safe" tag causes flask to _not_ escape the rendered content. To remediate this, simply remove the `|safe` tag from the HTML above. No fix is is available and users are advised to manually edit their installation.
Overview
  • CVE ID
  • CVE-2024-22414
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-01-17T20:25:29.629Z
  • Last Modified Date
  • 2024-01-17T20:25:29.629Z
References
History
Created Old Value New Value Data Type Notes
2024-06-26 09:23:23 Added to TrackCVE