{ "id": "CVE-2024-22854", "sourceIdentifier": "cve@mitre.org", "published": "2024-02-16T09:15:08.533", "lastModified": "2024-02-16T13:37:51.433", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted by a remote attacker and visited by an authenticated user, allows open redirect and potential credential stealing using an injected HTML form." }, { "lang": "es", "value": "Se ha identificado una vulnerabilidad de inyecci\u00f3n de HTML basada en DOM en la p\u00e1gina principal de Darktrace Threat Visualizer versi\u00f3n 6.1.27 (versi\u00f3n del paquete 61050) y anteriores. Una URL, creada por un atacante remoto y visitada por un usuario autenticado, permite la redirecci\u00f3n abierta y el posible robo de credenciales mediante un formulario HTML inyectado." } ], "metrics": {}, "references": [ { "url": "https://tomekwasiak.pl/cve-2024-22854/", "source": "cve@mitre.org" } ] }