CVE-2024-45299

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-45299
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45299.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-45299
Aliases
  • GHSA-mcx6-25f8-8rqw
Published
2024-09-06T13:00:47.419Z
Modified
2025-12-05T06:16:05.893300Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
alf.io's preloaded data as json is not escaped correctly
Details

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the preloaded data as json is not escaped correctly, the administrator / event admin could break their own install by inserting non correctly escaped text. The Content-Security-Policy directive blocks any potential script execution. The administrator or event administrator can override the texts for customization purpose. The texts are not properly escaped. Version 2.0-M5 fixes this issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-116"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45299.json"
}
References

Affected packages

Git / github.com/alfio-event/alf.io

Affected ranges

Type
GIT
Repo
https://github.com/alfio-event/alf.io
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.10
1.10-RC1
1.10-RC2
1.10.1
1.11
1.12
1.12-RC1
1.12-RC2
1.12-RC3
1.12-RC4
1.13
1.13-RC1
1.13-RC2
1.13-RC3
1.14
1.14-RC1
1.14-RC2
1.14.1
1.4
1.4-RC2
1.4.1
1.5
1.6
1.7
1.8
1.8-RC1
1.8-RC2
1.9
1.9.1

2.*

2.0-M0
2.0-M1
2.0-M1-1906
2.0-M1-1906.1
2.0-M2
2.0-M3
2.0-M4
2.0-M4-2204
2.0-M4-2301
2.0-M4-2304
2.0-M4.RC1
2.0-M4.RC2
2.0-M4.RC3
2.0-M4.RC4

alfio-1.*

alfio-1.0
alfio-1.1
alfio-1.2
alfio-1.3
alfio-1.3-beta1
alfio-1.3.1
alfio-1.3.2
alfio-1.3.3

v1.*

v1.0-pre-rename
v1.0-pre-rename-v2
v1.0-pre-rename-v3