Javascript in Markdown Notes Fields Vulnerability in InvenTree Inventory Management System
CVE-2024-47610
What is CVE-2024-47610?
InvenTree Inventory Management System has a vulnerability that enables registered users to inject JavaScript code through markdown note fields. This code is executed when other logged-in users access the same page, potentially compromising user sessions and data integrity. The issue is resolved in versions 0.16.5 and later through the implementation of HTML sanitization within the 'easymde' markdown rendering library and backend validation to prevent the storage of malicious markdown. All users are strongly encouraged to upgrade to the latest version to mitigate any risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
InvenTree < 0.16.5
References
CVSS V3.1
Timeline
Vulnerability published
