CVE-2024-28434: XSS
Published Mar 25, 2024
·Updated
The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code.
Affected Software
2 affected components
Twenty CRM platform
Twenty Twenty=0.3.0
Event History
Mar 25, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28434?
CVE-2024-28434 is classified as a moderate severity vulnerability due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2024-28434?
To mitigate CVE-2024-28434, users should implement input validation to restrict file uploads and sanitize any user-uploaded content.
3
What versions of the Twenty CRM platform are affected by CVE-2024-28434?
CVE-2024-28434 affects version 0.3.0 of the Twenty CRM platform.
4
What type of attack does CVE-2024-28434 allow?
CVE-2024-28434 allows attackers to execute arbitrary JavaScript code via crafted SVG file uploads.
5
Is CVE-2024-28434 still present in later versions of Twenty CRM?
CVE-2024-28434 has not been remediated in later versions of Twenty CRM unless specifically patched by the vendor.