Описание
NPR Visuals Team Pym.js version versions 0.4.2 up to 1.3.1 contains a Cross ite Request Forgery (CSRF) vulnerability in Pym.js _onNavigateToMessage function. https://github.com/nprapps/pym.js/blob/master/src/pym.js#L573 that can result in Arbitrary javascript code execution. This attack appear to be exploitable via Attacker gains full javascript access to pages with Pym.js embeds when user visits an attacker crafted page.. This vulnerability appears to have been fixed in versions 1.3.2 and later.
Ссылки
- Vendor Advisory
- Product
- Third Party Advisory
- Vendor Advisory
- Product
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.4.2 (включая) до 1.3.1 (включая)
cpe:2.3:a:npr:pym.js:*:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00296
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
EPSS
Процентиль: 53%
0.00296
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352