Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1.
History

Tue, 01 Apr 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Dpgaspar
Dpgaspar flask-appbuilder
CPEs cpe:2.3:a:dpgaspar:flask-appbuilder:*:*:*:*:*:*:*:*
Vendors & Products Dpgaspar
Dpgaspar flask-appbuilder

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-02-28T15:34:02.490Z

Updated: 2024-08-08T19:24:18.993Z

Reserved: 2024-02-19T14:43:05.991Z

Link: CVE-2024-27083

cve-icon Vulnrichment

Updated: 2024-08-02T00:27:57.821Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-29T01:44:19.387

Modified: 2025-04-01T15:22:28.893

Link: CVE-2024-27083

cve-icon Redhat

No data.