CVE-2024-26362: Code Injection
Published Apr 10, 2024
·Updated
HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.
Affected Software
4 affected components
Enpass Password Manager Desktop Client
All of the following
Enpass Password Manager=6.9.2
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Apr 10, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-26362?
CVE-2024-26362 is rated as a high severity vulnerability due to its potential to allow attackers to run arbitrary HTML code.
2
How does CVE-2024-26362 impact Enpass Password Manager?
CVE-2024-26362 allows attackers to exploit the HTML injection vulnerability to create crafted notes that can execute malicious HTML code.
3
Which versions of Enpass Password Manager are affected by CVE-2024-26362?
CVE-2024-26362 affects Enpass Password Manager Desktop Client version 6.9.2.
4
How do I fix CVE-2024-26362?
To fix CVE-2024-26362, update the Enpass Password Manager Desktop Client to the latest version that has addressed this vulnerability.
5
Can CVE-2024-26362 affect both Windows and Linux users?
Yes, CVE-2024-26362 affects the Enpass Password Manager Desktop Client on both Windows and Linux platforms.