Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Riyush Ghimire

#45516of 56,330
6.1Total CVSS
Vulnerabilities · 1
PT-2024-21798
6.1
2024-02-29
Unknown · Docassemble · CVE-2024-27290
**Name of the Vulnerable Software and Affected Versions** Docassemble versions prior to 1.4.97 **Description** The issue allows a user to type HTML into a field, including the field for the user's name, and then that HTML could be displayed on the screen as HTML. The HTML can also contain `<script>` tags, allowing JavaScript to execute on the page. **Recommendations** For versions prior to 1.4.97, update to version 1.4.97 of the master branch to resolve the issue. If upgrading is not possible, manually apply the changes of the specified commit and restart the server.