Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-22191

18
FAUCET Score

CVE-2024-22191 is a stored cross-site scripting (XSS) vulnerability affecting Avo, a framework for Ruby on Rails admin panels, specifically versions 3.2.3 and 2.46.0. An attacker could exploit this by injecting malicious JavaScript into the key_value field, which is not properly sanitized before being rendered in HTML. This could lead to the theft of sensitive information, account hijacking, or redirection to malicious websites. The vulnerability has a CVSS score of 5.4 (Medium), indicating a network-based attack requiring low privileges and user interaction, with potential for low impact on confidentiality and integrity. The EPSS score is low, suggesting a low probability of exploitation. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. Users are advised to upgrade to Avo versions 3.2.4 or 2.47.0 to remediate this issue.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.47.0CPE matchmatch criteria
cpe:2.3:a:avohq:avo:*:*:*:*:*:ruby:*:*
>= 3.0.0, < 3.3.0CPE matchmatch criteria
cpe:2.3:a:avohq:avo:*:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.1
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.74%
Probability of exploitation in next 30 days
EPSS Percentile
51.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0075 is in the 86th percentile among its peer group of 15,224 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
rubygemspatch availablevia ghsa
Product: avoFixed in: 3.2.4
rubygemspatch availablevia ghsa
Product: avoFixed in: 2.47.0

Vendor Advisories (1)

rubygemsGHSA-ghjv-mh6x-7q6hhigh

avo vulnerable to stored cross-site scripting (XSS) in key_value field

Jan 16, 2024

References

github.com / avo-hq/avo/commit/51bb80b181cd8e31744bdc4e7f9b501c81172347
Patch
github.com / avo-hq/avo/commit/fc92a05a8556b1787c8694643286a1afa6a71258
Patch
github.com / avo-hq/avo/security/advisories/GHSA-ghjv-mh6x-7q6h
ExploitVendor Advisory