CVE-2024-27092

Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with Spoofed Content as Hoppscotch. Part of payload (external link) is presented in clickable form - easier to achieve own goals by malicious actors. This issue is fixed in 2023.12.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hoppscotch:hoppscotch:*:*:*:*:*:*:*:*

History

01 Apr 2025, 15:22

Type Values Removed Values Added
First Time Hoppscotch
Hoppscotch hoppscotch
CPE cpe:2.3:a:hoppscotch:hoppscotch:*:*:*:*:*:*:*:*
References () https://github.com/hoppscotch/hoppscotch/blob/main/packages/hoppscotch-backend/src/team-invitation/team-invitation.service.ts#L153 - () https://github.com/hoppscotch/hoppscotch/blob/main/packages/hoppscotch-backend/src/team-invitation/team-invitation.service.ts#L153 - Product
References () https://github.com/hoppscotch/hoppscotch/commit/6827e97ec583b2534cdc1c2f33fa44973a0c2bf5 - () https://github.com/hoppscotch/hoppscotch/commit/6827e97ec583b2534cdc1c2f33fa44973a0c2bf5 - Patch
References () https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-8r6h-8r68-q3pp - () https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-8r6h-8r68-q3pp - Exploit, Third Party Advisory

21 Nov 2024, 09:03

Type Values Removed Values Added
References () https://github.com/hoppscotch/hoppscotch/blob/main/packages/hoppscotch-backend/src/team-invitation/team-invitation.service.ts#L153 - () https://github.com/hoppscotch/hoppscotch/blob/main/packages/hoppscotch-backend/src/team-invitation/team-invitation.service.ts#L153 -
References () https://github.com/hoppscotch/hoppscotch/commit/6827e97ec583b2534cdc1c2f33fa44973a0c2bf5 - () https://github.com/hoppscotch/hoppscotch/commit/6827e97ec583b2534cdc1c2f33fa44973a0c2bf5 -
References () https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-8r6h-8r68-q3pp - () https://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-8r6h-8r68-q3pp -

29 Feb 2024, 01:44

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-29 01:44

Updated : 2025-04-01 15:22


NVD link : CVE-2024-27092

Mitre link : CVE-2024-27092

CVE.ORG link : CVE-2024-27092


JSON object : View

Products Affected

hoppscotch

  • hoppscotch
CWE
CWE-20

Improper Input Validation

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')