Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6m63-xcvc-h2vg

Опубликовано: 29 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources.

Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources.

EPSS

Процентиль: 28%
0.00098
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources.

EPSS

Процентиль: 28%
0.00098
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79