Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2760 | Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a color column or entry is rendered. Filament v3.2.115 fixes this issue. |
Github GHSA |
GHSA-9h9q-qhxg-89xr | Filament has unvalidated ColorColumn and ColorEntry values that can be used for Cross-site Scripting |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 07 Oct 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Filamentphp
Filamentphp filament |
|
| CPEs | cpe:2.3:a:filamentphp:filament:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Filamentphp
Filamentphp filament |
Fri, 27 Sep 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Sep 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a color column or entry is rendered. Filament v3.2.115 fixes this issue. | |
| Title | Filament has unvalidated ColorColumn and ColorEntry values that can be used for Cross-site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-27T21:56:30.280Z
Reserved: 2024-09-19T22:32:11.963Z
Link: CVE-2024-47186
Updated: 2024-09-27T21:49:15.814Z
Status : Analyzed
Published: 2024-09-27T21:15:03.443
Modified: 2024-10-07T13:30:55.640
Link: CVE-2024-47186
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA