Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gjh4-fcv3-whpq

Опубликовано: 04 сент. 2019
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-Site Scripting in webtorrent

Versions of webtorrent prior to 0.107.6 are vulnerable to Cross-Site Scripting. webtorrent servers started with torrent.createServer() lists a torrent's title and files in the index page without sanitization. This allows attackers to execute arbitrary JavaScript in the victim's browser through files with names containing the malicious payload. The issue is mitigated due to the fact that the server only allows fetching data pieces from the torrent.

Recommendation

Upgrade to version 0.107.6 or later.

Пакеты

Наименование

webtorrent

npm
Затронутые версииВерсия исправления

< 0.107.6

0.107.6

EPSS

Процентиль: 43%
0.00208
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 6 лет назад

WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.

EPSS

Процентиль: 43%
0.00208
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79