BIT-appsmith-2022-39824

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/appsmith/BIT-appsmith-2022-39824.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-appsmith-2022-39824
Aliases
Published
2024-03-06T10:50:47.399Z
Modified
2025-04-03T14:40:37.652Z
Summary
[none]
Details

Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code from the server via the currentItem property of the list widget, e.g., to perform DoS attacks or achieve an information leak.

Database specific
{
    "cpes": [
        "cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / appsmith

Package

Name
appsmith
Purl
pkg:bitnami/appsmith

Severity

  • 8.9 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.15