Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the currentItem property of the list widget, e.g., to perform DoS attacks or achieve an information leak.
References
Link Resource
https://github.com/FCncdn/Appsmith-Js-Injection-POC Exploit Third Party Advisory
https://github.com/appsmithorg/appsmith/releases Release Notes Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-09-05T02:54:02

Updated: 2022-09-05T02:54:02

Reserved: 2022-09-05T00:00:00


Link: CVE-2022-39824

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-09-05T03:15:07.627

Modified: 2022-09-09T16:47:57.653


Link: CVE-2022-39824

JSON object: View

cve-icon Redhat Information

No data.

CWE