Vulnerability Description
Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker to hijack a user's account. The sign-in page takes the `redirectPath` parameter from the URL. If a user clicks on a link where the `redirectPath` parameter has a javascript scheme, the attacker that crafted the link may be able to execute arbitrary JavaScript with the privileges of the user. Version 2.24.0 contains a patch for this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Typebot | Typebot | < 2.24.0 |
Related Weaknesses (CWE)
References
- https://github.com/baptisteArno/typebot.io/blob/v2.23.0/apps/builder/src/featureProduct
- https://github.com/baptisteArno/typebot.io/commit/d0be29e25732c410b561cbc3c5607cPatch
- https://github.com/baptisteArno/typebot.io/security/advisories/GHSA-mx2f-9mcr-8jExploitVendor Advisory
- https://github.com/baptisteArno/typebot.io/blob/v2.23.0/apps/builder/src/featureProduct
- https://github.com/baptisteArno/typebot.io/commit/d0be29e25732c410b561cbc3c5607cPatch
- https://github.com/baptisteArno/typebot.io/security/advisories/GHSA-mx2f-9mcr-8jExploitVendor Advisory
FAQ
What is CVE-2024-30264?
CVE-2024-30264 is a vulnerability with a CVSS score of 8.1 (HIGH). Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker to hijack a user's account. The sign-i...
How severe is CVE-2024-30264?
CVE-2024-30264 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-30264?
Check the references section above for vendor advisories and patch information. Affected products include: Typebot Typebot.