CVE-2024-4216: XSS vulnerability in /settings/store API response json payload in pgAdmin 4
Published May 2, 2024
·Updated
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
Affected Software
3 affected componentsFixes available
pip/pgAdmin4<=8.5
8.6
pgAdmin Pgadmin 4 Postgresql<8.6
Fedoraproject Fedora=40
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pgAdmin4to a version that resolves this vulnerability.Fixed in 8.6
Event History
May 2, 2024
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
WeaknessAffected Software
Advisory Published
via GitHub·06:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-4216?
CVE-2024-4216 has a high severity due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2024-4216?
To fix CVE-2024-4216, upgrade pgAdmin to version 8.6 or higher.
3
What versions of pgAdmin are affected by CVE-2024-4216?
pgAdmin versions 8.5 and earlier are affected by CVE-2024-4216.
4
What type of vulnerability is CVE-2024-4216?
CVE-2024-4216 is an XSS vulnerability located in the /settings/store API response.
5
Can CVE-2024-4216 lead to client-side attacks?
Yes, CVE-2024-4216 can allow attackers to execute malicious scripts on the client side.