GHSA-rwcv-whm8-fmxmMediumCVSS 6.1
GeoNode: Stored XSS to full account takeover
🔗 CVE IDs covered (1)
📋 Description
An issue exists within GEONODE where the current rich text editor is vulnerable to Stored XSS. The applications cookies are set securely, but it is possible to retrieve a victims CSRF token and issue a request to change another user's email address to perform a full account takeover. Due to the script element not impacting the CORS policy, requests will succeed.
🎯 Affected products1
- pip/geonode:>= 3.2.1, < 4.2.3
🔗 References (5)
- https://github.com/GeoNode/geonode/security/advisories/GHSA-rwcv-whm8-fmxm
- https://nvd.nist.gov/vuln/detail/CVE-2024-27091
- https://github.com/GeoNode/geonode/commit/e53bdeff331f4b577918927d60477d4b50cca02f
- https://github.com/pypa/advisory-database/tree/main/vulns/geonode/PYSEC-2024-320.yaml
- https://github.com/advisories/GHSA-rwcv-whm8-fmxm