CVE-2024-53272: GHSL-2024-109: Reflected XSS in /login in habitica
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The login and social media function in RegisterLoginReset.vue contains two reflected XSS vulnerabilities due to an incorrect sanitization function. An attacker can specify a malicious redirectTo parameter to trigger the vulnerability, giving the attacker control of the victim’s account when a victim registers or logins with a specially crafted link. Version 5.28.5 contains a patch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53272?
CVE-2024-53272 is classified as a reflected cross-site scripting vulnerability that can lead to serious security issues if exploited.
How do I fix CVE-2024-53272?
To mitigate CVE-2024-53272, update Habitica to version 5.28.5 or later, which includes patches for the identified vulnerabilities.
What are the affected versions for CVE-2024-53272?
CVE-2024-53272 affects Habitica versions prior to 5.28.5.
What components are vulnerable in CVE-2024-53272?
The vulnerabilities in CVE-2024-53272 are located in the `login` and `social media` functions within the RegisterLoginReset.vue file.
Who is impacted by CVE-2024-53272?
Users of Habitica prior to version 5.28.5 may be impacted by CVE-2024-53272 due to the reflected XSS vulnerabilities.