VYPR
Unrated severityNVD Advisory· Published Sep 6, 2024· Updated Sep 6, 2024

alf.io's preloaded data as json is not escaped correctly

CVE-2024-45299

Description

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the preloaded data as json is not escaped correctly, the administrator / event admin could break their own install by inserting non correctly escaped text. The Content-Security-Policy directive blocks any potential script execution. The administrator or event administrator can override the texts for customization purpose. The texts are not properly escaped. Version 2.0-M5 fixes this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Alfio Event/Alf.iollm-fuzzy2 versions
    <2.0-M5+ 1 more
    • (no CPE)range: <2.0-M5
    • (no CPE)range: < 2.0-M5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.