CVE-2024-56357
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Dec 20, 2024
Updated: Mar 12, 2025
CWE ID 79
Summary
CVE-2024-56357 is a vulnerability affecting the grist-core spreadsheet hosting server. Malicious documents or forms could lead to account compromise due to the server's acceptance of `javascript:` schemes in custom widget URLs and form redirect URLs. Users are strongly advised to upgrade to version 1.3.1 to mitigate this risk. Those unable to upgrade should exercise caution when interacting with documents and forms from untrusted sources.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.