CVE-2024-47186 | Filament has unvalidated ColorColumn and ColorEntry values that can be used for Cross-site Scripting
Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2.114 are affected by a cross-site scripting (XSS) vulnerability. If values passed to a `ColorColumn` or `ColumnEntry` are not valid and contain a specific set of characters, applications are vulnerable to XSS attack against a user who opens a page on which a color column or entry is rendered. Filament v3.2.115 fixes this issue.
Conclusion & alert: CVE-2024-47186 is rated Moderate Risk (51.8/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.09%).Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2024-47186
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
GHSA-9h9q-qhxg-89xr · Severity: medium · Ecosystem: composer — Filament has unvalidated ColorColumn and ColorEntry values that can be used for Cross-site Scripting
Affected software / configurations for CVE-2024-47186