CVE-2024-47186

Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a color column or entry is rendered. Filament v3.2.115 fixes this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:filamentphp:filament:*:*:*:*:*:*:*:*

History

07 Oct 2024, 13:30

Type Values Removed Values Added
CPE cpe:2.3:a:filamentphp:filament:*:*:*:*:*:*:*:*
First Time Filamentphp filament
Filamentphp
References () https://github.com/filamentphp/filament/commit/df7989352464d08eda5837ef50f9997fad902316 - () https://github.com/filamentphp/filament/commit/df7989352464d08eda5837ef50f9997fad902316 - Patch
References () https://github.com/filamentphp/filament/releases/tag/v3.2.115 - () https://github.com/filamentphp/filament/releases/tag/v3.2.115 - Release Notes
References () https://github.com/filamentphp/filament/security/advisories/GHSA-9h9q-qhxg-89xr - () https://github.com/filamentphp/filament/security/advisories/GHSA-9h9q-qhxg-89xr - Vendor Advisory

30 Sep 2024, 12:45

Type Values Removed Values Added
Summary
  • (es) Filament es una colección de componentes full-stack para el desarrollo de Laravel. Las versiones de Filament desde la v3.0.0 hasta la v3.2.114 se ven afectadas por una vulnerabilidad de cross site scripting (XSS). Si los valores que se pasan a `ColorColumn` o `ColumnEntry` no son válidos y contienen un conjunto específico de caracteres, las aplicaciones son vulnerables a ataques XSS contra un usuario que abre una página en la que se representa una columna o entrada de color. Filament v3.2.115 corrige este problema.

27 Sep 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-27 21:15

Updated : 2024-10-07 13:30


NVD link : CVE-2024-47186

Mitre link : CVE-2024-47186

CVE.ORG link : CVE-2024-47186


JSON object : View

Products Affected

filamentphp

  • filament
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')