Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhhv-ggjx-q9j2

Опубликовано: 31 окт. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

Glossarizer Cross-site Scripting vulnerability

Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored XSS. Attackers can append a XSS payload to a word that has a corresponding glossary entry.

Пакеты

Наименование

glossarizer

npm
Затронутые версииВерсия исправления

<= 1.5.2

Отсутствует

EPSS

Процентиль: 30%
0.00112
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9.9
nvd
больше 1 года назад

Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored XSS. Attackers can append a XSS payload to a word that has a corresponding glossary entry.

EPSS

Процентиль: 30%
0.00112
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79