CVE Vulnerabilities

CVE-2023-30949

Improper Use of Validation Framework

Published: Jul 26, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the pages content, which could lead to phishing attacks.

Weakness

The product does not use, or incorrectly uses, an input validation framework that is provided by the source language or an independent library.

Affected Software

NameVendorStart VersionEnd Version
SlatePalantir*6.207.0 (excluding)

Potential Mitigations

References