CVE-2024-27290
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Mar 21, 2024
CWE ID 79
Summary
CVE-2024-27290 is a vulnerability affecting Docassemble, an expert system for guided interviews and document assembly. Before version 1.4.97, users could input HTML code into certain fields, such as the user name field. This HTML code could then be displayed on the screen as executable HTML, posing a security risk. This issue has been addressed in version 1.4.97 of the master branch, which includes a patch to prevent the execution of user-supplied HTML.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.