CVE-2024-27091 describes a Stored Cross-Site Scripting (XSS) vulnerability in GeoNode, a geospatial content management system. An attacker can exploit a flaw in the rich text editor to inject malicious scripts. This medium-severity vulnerability (CVSS 6.1) allows for the retrieval of a victim's CSRF token, enabling an attacker to change another user's email address and achieve full account takeover. While cookies are set securely, the XSS bypasses CORS policies, allowing successful malicious requests. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. The issue is resolved in GeoNode version 4.2.3.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
> 3.2.0, < 4.2.3CPE matchmatch criteria | cpe:2.3:a:geosolutionsgroup:geonode:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.