Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wv8q-r932-8hc7

Опубликовано: 13 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Svelte vulnerable to XSS when using objects during server-side rendering

The package svelte before 3.49.0 is vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.

Пакеты

Наименование

svelte

npm
Затронутые версииВерсия исправления

< 3.49.0

3.49.0

EPSS

Процентиль: 73%
0.00776
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.

EPSS

Процентиль: 73%
0.00776
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79