Unrated severityNVD Advisory· Published Dec 20, 2024· Updated Dec 24, 2024
Cross-site Scripting vulnerability through HyperLink cells in grist-core
CVE-2024-56359
Description
grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink cell using a control modifier (meaning for example Ctrl+click) could have their account compromised, since the link could use the javascript: scheme and be evaluated in the context of their current page. This issue has been patched in version 1.3.2. Users are advised to upgrade. Users unable to upgrade should avoid clicking on HyperLink cell links using a control modifier in documents prepared by people they do not trust.
Affected products
1- Range: < 1.3.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/gristlabs/grist-core/commit/a792bdc43b456dbdd6fdc50d8747f4c349fab2f4mitrex_refsource_MISC
- github.com/gristlabs/grist-core/security/advisories/GHSA-qv69-5cj2-53r9mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.