CyberRota Analysis
AI-GeneratedThe vulnerability in Capgo versions prior to 12.128.2 allows for HTML injection through the organization settings endpoint, enabling attackers to manipulate the organization name field. This can lead to phishing attacks by redirecting users to untrusted websites, posing a risk of reputational damage. Organizations using affected versions should prioritize patching to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attackers to inject malicious HTML content. Attackers can craft payloads in the organization name field to redirect users to untrusted websites, enabling phishing attacks and reputational damage.