Description

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This potentially allows an authenticated attacker to inject malicious code into the dashboard, which is then executed or rendered in the context of an administrator's browser when viewing the injected content. However, it is important to note that the default Content Security Policy (CSP) of the application blocks most exploitation paths, significantly mitigating the potential impact.

INFO

Published Date :

2024-09-13T00:00:00.000Z

Last Modified :

2025-03-18T18:51:04.712Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-39926 vulnerability.

Vendors Products
Dani-garcia
  • Vaultwarden
Vaultwarden
  • Vaultwarden

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact