CVE-2023-27474
Description
Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset URL are vulnerable to an HTML injection attack through the use of query parameters in the reset URL. An attacker could exploit this to email users urls to the servers domain but which may contain malicious code. The problem has been resolved and released under version 9.23.0. People relying on a custom password reset URL should upgrade to 9.23.0 or later, or remove the custom reset url from the configured allow list. Users are advised to upgrade. Users unable to upgrade may disable the custom reset URL allow list as a workaround.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
directusnpm | < 9.23.0 | 9.23.0 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/directus/directus/pull/17120nvdPatchWEB
- github.com/advisories/GHSA-4hmq-ggrm-qfc6ghsaADVISORY
- github.com/directus/directus/issues/17119nvdIssue TrackingMailing ListThird Party AdvisoryWEB
- github.com/directus/directus/security/advisories/GHSA-4hmq-ggrm-qfc6nvdIssue TrackingVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-27474ghsaADVISORY
News mentions
0No linked articles in our index yet.