CVE-2024-49751
CVSS V2 None
CVSS V3 None
Description
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Prior to commit 5d118a902872d7941f099ad1fb918e2421e79ccd, a user could inject HTML through SaaS signup inputs. The user who injected the unsafe HTML code would only affect themselves and would not affect other users. Commit 5d118a902872d7941f099ad1fb918e2421e79ccd patches this bug.
Overview
- CVE ID
- CVE-2024-49751
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-23T15:45:12.348Z
- Last Modified Date
- 2024-10-23T16:27:13.106Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/frappe/press/security/advisories/GHSA-rf69-h96f-rf2j | x_refsource_CONFIRM |
https://github.com/frappe/press/commit/5d118a902872d7941f099ad1fb918e2421e79ccd | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-49751 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-49751 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-24 13:31:12 | Added to TrackCVE |