CVE-2024-53273: GHSL-2024-110: Reflected XSS in /register in habitica
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The register function in RegisterLoginReset.vue contains a reflected XSS vulnerability due to an incorrect sanitization function. An attacker can specify a malicious redirectTo parameter to trigger the vulnerability, giving the attacker control of the victim’s account when a victim registers or logins with a specially crafted link. Version 5.28.5 contains a patch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53273?
CVE-2024-53273 is classified as a medium severity reflected cross-site scripting vulnerability.
How do I fix CVE-2024-53273?
To fix CVE-2024-53273, update Habitica to version 5.28.5 or later.
What is affected by CVE-2024-53273?
CVE-2024-53273 affects Habitica versions prior to 5.28.5.
What types of attacks can CVE-2024-53273 facilitate?
CVE-2024-53273 can facilitate reflected cross-site scripting attacks, allowing attackers to execute scripts in users' browsers.
Where is the vulnerability located in Habitica for CVE-2024-53273?
The vulnerability in CVE-2024-53273 is located in the `register` function within the `RegisterLoginReset.vue` file.