CVE-2024-30264: typebot.io: `GHSL-2024-040`
Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker to hijack a user's account. The sign-in page takes the redirectPath parameter from the URL. If a user clicks on a link where the redirectPath parameter has a javascript scheme, the attacker that crafted the link may be able to execute arbitrary JavaScript with the privileges of the user. Version 2.24.0 contains a patch for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30264?
CVE-2024-30264 is classified as a high-severity reflected cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-30264?
To mitigate CVE-2024-30264, upgrade to Typebot version 2.24.0 or later.
What impact does CVE-2024-30264 have on users?
CVE-2024-30264 may allow attackers to hijack user accounts through maliciously crafted links.
Which versions of Typebot are affected by CVE-2024-30264?
CVE-2024-30264 affects all versions of Typebot prior to 2.24.0.
Where can I find more information about CVE-2024-30264?
More information about CVE-2024-30264 can typically be found in security advisories for Typebot.