Javascript in Markdown Notes Fields Vulnerability in InvenTree Inventory Management System
CVE-2024-47610
7.3HIGH
What is CVE-2024-47610?
InvenTree Inventory Management System has a vulnerability that enables registered users to inject JavaScript code through markdown note fields. This code is executed when other logged-in users access the same page, potentially compromising user sessions and data integrity. The issue is resolved in versions 0.16.5 and later through the implementation of HTML sanitization within the 'easymde' markdown rendering library and backend validation to prevent the storage of malicious markdown. All users are strongly encouraged to upgrade to the latest version to mitigate any risks.
Affected Version(s)
InvenTree < 0.16.5
