Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h685-83w4-3ph3

Опубликовано: 21 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

iziModal Cross-site Scripting vulnerability

iziModal is a modal plugin with jQuery. Versions prior to 1.6.1 are vulnerable to cross-site scripting (XSS) when handling untrusted modal titles. An attacker who is able to influence the field title when creating a iziModal instance is able to supply arbitrary html or javascript code that will be rendered in the context of a user, potentially leading to XSS. Version 1.6.1 contains a patch for this issue

Пакеты

Наименование

izimodal

npm
Затронутые версииВерсия исправления

< 1.6.1

1.6.1

EPSS

Процентиль: 63%
0.00442
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

iziModal is a modal plugin with jQuery. Versions prior to 1.6.1 are vulnerable to cross-site scripting (XSS) when handling untrusted modal titles. An attacker who is able to influence the field `title` when creating a `iziModal` instance is able to supply arbitrary `html` or `javascript` code that will be rendered in the context of a user, potentially leading to `XSS`. Version 1.6.1 contains a patch for this issue

EPSS

Процентиль: 63%
0.00442
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79