Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrv8-4h2c-vxmj

Опубликовано: 26 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks.

angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks.

EPSS

Процентиль: 45%
0.00221
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 2 года назад

angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks.

EPSS

Процентиль: 45%
0.00221
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79