CVE-2024-27092: Content spoofing - real Hoppscotch emails
Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with Spoofed Content as Hoppscotch. Part of payload (external link) is presented in clickable form - easier to achieve own goals by malicious actors. This issue is fixed in 2023.12.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27092?
CVE-2024-27092 is classified as a moderate severity vulnerability.
How do I fix CVE-2024-27092?
To fix CVE-2024-27092, update to the latest version of Hoppscotch beyond 2023.12.6 where the validation issue is addressed.
What type of attack is facilitated by CVE-2024-27092?
CVE-2024-27092 facilitates email spoofing attacks by allowing malicious content to be sent disguised as legitimate Hoppscotch communication.
Who is affected by CVE-2024-27092?
CVE-2024-27092 affects users of Hoppscotch versions up to and including 2023.12.6.
What fields lack validation in CVE-2024-27092?
CVE-2024-27092 specifically lacks validation in fields such as Label and TeamName during the team editing process.