CVE Feed

    Dashboard / CVE / CVE-2024-22414

    CVE-2024-22414

    flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitrary javascript code. The html template `user.html` contains the following code snippet to render comments made by a user: `<div class="content" tag="content">{{comment[2]|safe}}</div>`. Use of the "safe" tag causes flask to _not_ escape the rendered content. To remediate this, simply remove the `|safe` tag from the HTML above. No fix is is available and users are advised to manually edit their installation.

    Published:Jan 17, 2024
    Last Modified:Jun 17, 2025
    EPS:Jan 17, 2024
    EPSS Score:0.002
    CVSS Score:6.5

    Affected Products

    Vendor
    Dogukanurker
    Product
    Flaskblog

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High