CyberRota Analysis
AI-GeneratedSpiderFoot is vulnerable due to its failure to properly HTML-escape correlation titles derived from external scan data, allowing attackers to inject malicious HTML elements. This critical vulnerability can lead to the execution of scripts in the operator's browser, potentially compromising sensitive information such as API keys. Organizations using SpiderFoot should prioritize immediate remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.