CVE-2024-54128

Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML Injection. This vulerability is fixed in 10.13.4 and 11.2.0.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:*
cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:*

History

19 Nov 2025, 14:47

Type Values Removed Values Added
Summary
  • (es) Directus es una API en tiempo real y un panel de control de aplicaciones para administrar el contenido de bases de datos SQL. La función de comentarios implementó un filtro para evitar que los usuarios agreguen caracteres restringidos, como etiquetas HTML. Sin embargo, este filtro opera en el lado del cliente, lo que puede eludirse, lo que hace que la aplicación sea vulnerable a la inyección de HTML. Esta vulnerabilidad se solucionó en 10.13.4 y 11.2.0.
References () https://github.com/directus/directus/security/advisories/GHSA-r6wx-627v-gh2f - () https://github.com/directus/directus/security/advisories/GHSA-r6wx-627v-gh2f - Exploit, Vendor Advisory
CPE cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:*
First Time Monospace
Monospace directus

05 Dec 2024, 19:15

Type Values Removed Values Added
Summary (en) Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML Injection. (en) Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding restricted characters, such as HTML tags. However, this filter operates on the client-side, which can be bypassed, making the application vulnerable to HTML Injection. This vulerability is fixed in 10.13.4 and 11.2.0.

05 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-05 17:15

Updated : 2025-11-19 14:47


NVD link : CVE-2024-54128

Mitre link : CVE-2024-54128

CVE.ORG link : CVE-2024-54128


JSON object : View

Products Affected

monospace

  • directus
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)