OctoPrint
cpe:2.3:a:octoprint:octoprint:*:*:*:*:*:*:*
- <= 1.11.3
A cross-site scripting vulnerability has been identified in OctoPrint versions through 1.11.3. This issue allows the injection of arbitrary HTML and JavaScript into Action Command notifications and prompt popups generated by the printer. An attacker could exploit this vulnerability by convincing a victim to print a specially crafted file, potentially disrupting ongoing prints, extracting sensitive information (including configuration settings, if the user has the necessary permissions), or performing actions on behalf of the user within OctoPrint.
Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's browser.
Users can upgrade to OctoPrint version 1.11.4, where this vulnerability is patched. Alternatively, OctoPrint administrators can disable popups for Action Command notifications and prompts by adjusting the settings in the OctoPrint interface.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.