Back

MEDIUM

Directus 10.13.0 - DOM-Based cross-site scripting (XSS) via layout_options

Published Aug 15, 2024

Description

Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that will be stored in the server and used by the client into an unsanitized DOM element. When chained with CVE-2024-6534, it could result in account takeover.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Fluid Attacks
Published Aug 15, 2024
Updated May 19, 2025
Reserved Jul 5, 2024

CISA Vulnrichment

Updated Aug 16, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Fluid Attacks
Published Aug 15, 2024
Updated May 19, 2025