CVE-2022-24864
Description
Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to /presale/join. User-controlled data is passed with no sanitization to SendGrid and injected into an email that is delivered to the [email protected]. If the email recipient is using an email program that is susceptible to XSS, then that email recipient will receive an email that may contain malicious XSS. Regardless if the email recipient’s mail program has vulnerabilities or not, the hacker can at the very least inject malicious HTML that modifies the body content of the email. There are currently no known workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:originprotocol:origin_website:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:originprotocol:origin_website:*:*:*:*:*:*:*:*range: <2022-01-10
- (no CPE)
- (no CPE)range: < c12d2f2
Patches
Vulnerability mechanics
References
3- github.com/OriginProtocol/origin-website/pull/617nvdPatchThird Party Advisory
- github.com/github/codeql/pull/7127nvdPatchThird Party Advisory
- github.com/OriginProtocol/origin-website/security/advisories/GHSA-v6fc-qwxx-m4h7nvdThird Party Advisory
News mentions
0No linked articles in our index yet.