CVE-2024-53386
CVE-2024-53386
Título es
CVE-2024-53386
Lun, 03/03/2025 – 07:15
Tipo
CWE-94
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-53386
Descripción en
Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
03/03/2025
03/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
4.90
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://gist.github.com/jackfromeast/31d56f1ad17673aabb6ab541e65a5534
https://github.com/piqnt/stage.js/blob/919f6e94b14242f6e6994141a9e1188439d306d5/lib/core.js#L158-L159
Enviar en el boletín
Off