cbcvebase.
CVE-2024-22411
published 2024-01-16

CVE-2024-22411: Avo is a framework to create admin panels for Ruby on Rails apps. In Avo 3 pre12, any HTML inside text that is passed to `error` or `succeed` in an…

PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.71%
52.1th percentile
Avo is a framework to create admin panels for Ruby on Rails apps. In Avo 3 pre12, any HTML inside text that is passed to `error` or `succeed` in an `Avo::BaseAction` subclass will be rendered directly without sanitization in the toast/notification that appears in the UI on Action completion. A malicious user could exploit this vulnerability to trigger a cross site scripting attack on an unsuspecting user. This issue has been addressed in the 3.3.0 and 2.47.0 releases of Avo. Users are advised to upgrade.

Affected

7 ranges
VendorProductVersion rangeFixed in
avo-hqavo< 2.47.02.47.0
avo-hqavo——
avo-hqavo>= 0 < 2.47.02.47.0
avo-hqavo>= 3.0.0.beta1 < 3.3.03.3.0
avohqavo< 2.47.02.47.0
avohqavo——
avohqavo>= 3.0.2 < 3.3.03.3.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.