GHSL-2024-109: _GHSL-2024-111: Reflected Cross-Site Scripting (XSS) vulnerabilities in habitica
Published Dec 11, 2024
·Updated
Multiple reflected XSS vulnerabilities exist in the registration and login forms of habitica, giving the attacker control of the victim’s account when a victim registers or logins with a specially crafted link.
Affected Software
1 affected component
habitica habitica
Event History
Dec 11, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What user interaction is required for exploitation?
A victim must register or log in through a specially crafted link controlled by the attacker. The issue is reflected XSS in Habitica’s registration and login forms.
2
What is the likely impact if exploitation succeeds?
The attacker can gain control of the victim’s account.
3
Which release includes the referenced fix?
The provided references identify Habitica release v5.25.2 and commit 6cadaddc602cfd042b9f57b32a1619d437169038.