Javascript in Markdown Notes Fields Vulnerability in InvenTree Inventory Management System
CVE-2024-47610

7.3HIGH

Key Information:

Vendor

Inventree

Status
Vendor
CVE Published:
7 October 2024

What is CVE-2024-47610?

InvenTree Inventory Management System has a vulnerability that enables registered users to inject JavaScript code through markdown note fields. This code is executed when other logged-in users access the same page, potentially compromising user sessions and data integrity. The issue is resolved in versions 0.16.5 and later through the implementation of HTML sanitization within the 'easymde' markdown rendering library and backend validation to prevent the storage of malicious markdown. All users are strongly encouraged to upgrade to the latest version to mitigate any risks.

Affected Version(s)

InvenTree < 0.16.5

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.