Описание
The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.
Ссылки
- ExploitPatchThird Party Advisory
- Broken Link
- ExploitPatchThird Party Advisory
- ExploitPatchThird Party Advisory
- Broken Link
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.49.0 (исключая)
cpe:2.3:a:svelte:svelte:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 73%
0.00776
Низкий
5.4 Medium
CVSS3
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
больше 3 лет назад
Svelte vulnerable to XSS when using objects during server-side rendering
EPSS
Процентиль: 73%
0.00776
Низкий
5.4 Medium
CVSS3
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79