Feed/CVE-2024-6533
CVE-2024-6533LOWCVSS 3.4

CVE-2024-6533

Published Aug 14, 2024·Updated Aug 14, 2026

NVD Description

Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that will be stored in the server and used by the client into an unsanitized DOM element. When chained with CVE-2024-6534, it could result in account takeover.

Affected Packages (1)

directusNPM
Fixed in 11.3.3

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free