The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plugin or artifact. This field was not properly sanitized and can lead to cross-site scripting (XSS). This issue was resolved in Velociraptor 0.6.5-2.
2022-07-29T17:15:09.843
2024-11-21T07:11:24.620
Modified
CVSSv3.1: 4.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rapid7 | velociraptor | < 0.6.5-2 | Yes |