GHSA-ghjv-mh6x-7q6h

    Dashboard / Vulnerabilities / GHSA-ghjv-mh6x-7q6h

    GHSA-ghjv-mh6x-7q6h

    Published: 16 Jan 2024Last Modified: 10 Sept 2026

    Summary: avo vulnerable to stored cross-site scripting (XSS) in key_value field

    Details: ### Summary A **stored cross-site scripting (XSS)** vulnerability was found in the **key_value** field of Avo v3.2.3. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the victim's browser. ### Details The value of the key_value is inserted directly into the HTML code. In the current version of Avo (possibly also older versions), the value is not properly sanitized before it is inserted into the HTML code. This vulnerability can be exploited by an attacker to inject malicious JavaScript code into the key_value field. When a victim views the page containing the malicious code, the code will be executed in their browser. In [avo/fields/common/key_value_component.html.erb]( https://github.com/avo-hq/avo/blob/main/app/components/avo/fields/common/key_value_component.html.erb#L38C21-L38C33) the value is taken in lines **38** and **49** and seems to be interpreted directly as html in lines **44** and **55**. ### PoC ![POC](https://user-images.githubusercontent.com/26570201/295596307-5d4f563e-99c0-4981-a82e-fc42cfd902c5.gif) To reproduce the vulnerability, follow these steps: 1. Edit an entry with a key_value field. 2. Enter the following payload into the value field: ```POC\"> <script>alert( 'XSS in key_value' );</script> <strong>Outside-tag</strong``` 3. Save the entry. 4. Go to the index page and click on the eye icon next to the entry. The malicious JavaScript code will be executed and an alert box will be displayed. _On the show and edit page the alert seems not to pop up, but the strong tag breaks out of the expected html tag_ ### Impact This vulnerability could be used to steal sensitive information from victims that could be used to hijack victims' accounts or redirect them to malicious websites.

    Affected packages

    Package

    Name: avo

    Purl: pkg:gem/avo

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 3.0.0.beta1
    Fixed -3.2.4

    Affected versions

    3.0.0.beta1
    3.0.0.pre1
    3.0.0.pre10
    3.0.0.pre11
    3.0.0.pre12
    3.0.0.pre13
    3.0.0.pre14
    3.0.0.pre15
    3.0.0.pre16
    3.0.0.pre17
    3.0.0.pre18
    3.0.0.pre19
    3.0.0.pre2
    3.0.0.pre3
    3.0.0.pre4
    3.0.0.pre5
    3.0.0.pre6
    3.0.0.pre7
    3.0.0.pre8
    3.0.0.pre9
    3.0.1.beta1
    3.0.1.beta10
    3.0.1.beta11
    3.0.1.beta12
    3.0.1.beta13
    3.0.1.beta14
    3.0.1.beta15
    3.0.1.beta16
    3.0.1.beta17
    3.0.1.beta18
    3.0.1.beta19
    3.0.1.beta2
    3.0.1.beta20
    3.0.1.beta21
    3.0.1.beta22
    3.0.1.beta23
    3.0.1.beta24
    3.0.1.beta3
    3.0.1.beta4
    3.0.1.beta5
    3.0.1.beta6
    3.0.1.beta7
    3.0.1.beta8
    3.0.1.beta9
    3.0.2
    3.0.3
    3.0.4
    3.0.5
    3.0.6
    3.0.7
    3.0.8

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-ghjv-mh6x-7q6h | CVE-DB