Medium severity4.3NVD Advisory· Published Apr 26, 2024· Updated Jun 17, 2026
CVE-2024-33670
CVE-2024-33670
Description
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
passbolt/passbolt_apiPackagist | < 4.6.2 | 4.6.2 |
Affected products
3- Passbolt/Passbolt APIdescription
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-2pg6-vw9c-qhjvghsaADVISORY
- help.passbolt.com/incidents/reflective-html-injection-vulnerabilitynvdIssue TrackingVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-33670ghsaADVISORY
- www.passbolt.com/incidentsnvdIssue TrackingVendor Advisory
- github.com/passbolt/passbolt_api/commit/5c537849040990086dcd5013b5bb009e1dad3fb6ghsaWEB
- www.passbolt.com/security/morenvdProduct
News mentions
0No linked articles in our index yet.