← volver
CVE-2024-6533

Directus 10.13.0 - DOM-Based cross-site scripting (XSS) via layout_options

CVSS 5.4 MEDIUMEPSS 0.4%CWE-79
Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that will be stored in the server and used by the client into an unsanitized DOM element. When chained with CVE-2024-6534, it could result in account takeover.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Productos afectados
Directus · Directus

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →