Capgo
- < 12.128.2
A HTML injection vulnerability has been identified in Capgo versions prior to 12.128.2, specifically within the organization settings endpoint. This vulnerability allows attackers to inject malicious HTML into the organization name field, which can then be used to redirect users to untrusted websites. Such redirections could facilitate phishing attacks and cause reputational harm to the affected organization.
Exploitation of this vulnerability allows for HTML injection, which can be used to perform open redirection attacks. This could lead to phishing or malware distribution, abuse of the organization's brand, bypassing security measures, and a degradation of trust in the platform.
To reproduce this vulnerability, create a new account and organization in Capgo version prior to 12.128.2. During the organization setup, inject a HTML payload into the organization name field. After saving, invite a user to the team, which will trigger the HTML injection and execute the open redirection.
Users are advised to update to Capgo version 12.128.2 or later. Additionally, implement input sanitization to remove HTML tags, apply a strong Content Security Policy, and audit all input points for similar vulnerabilities.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.