Avo is a framework to create admin panels for Ruby on Rails apps. In Avo 3 pre12, any HTML inside text that is passed to error or succeed in an Avo::BaseAction subclass will be rendered directly without sanitization in the toast/notification that appears in the UI on Action completion. A malicious user could exploit this vulnerability to trigger a cross site scripting attack on an unsuspecting user. This issue has been addressed in the 3.3.0 and 2.47.0 releases of Avo. Users are advised to upgrade.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed_at": "2024-01-17T22:34:03Z",
"nvd_published_at": "2024-01-16T22:15:46Z",
"severity": "MODERATE",
"github_reviewed": true
}