GHSL-2024-111: GHSL-2024-109_GHSL-2024-111: Reflected Cross-Site Scripting (XSS) vulnerabilities in habitica
Published Dec 11, 2024
·Updated
Multiple reflected XSS vulnerabilities exist in the registration and login forms of habitica, giving the attacker control of the victim’s account when a victim registers or logins with a specially crafted link.
Affected Software
1 affected component
habitica habitica
Event History
Dec 11, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Which user actions are required for exploitation?
A victim must register or log in using a specially crafted link. The reflected XSS in the registration and login forms can then allow an attacker to take control of the victim’s account.
2
What release contains the fix?
The provided release reference identifies Habitica v5.25.2 as the relevant fixed release.