Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-25676

Опубликовано: 01 мая 2024
Источник: nvd
CVSS3: 4.7
EPSS Низкий

Описание

An issue was discovered in ViewerJS 0.5.8. A script from the component loads content via URL TAGs without properly sanitizing it. This leads to both open redirection and out-of-band resource loading.

EPSS

Процентиль: 34%
0.00141
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.7
github
почти 2 года назад

An issue was discovered in ViewerJS 0.5.8. A script from the component loads content via URL TAGs without properly sanitizing it. This leads to both open redirection and out-of-band resource loading.

EPSS

Процентиль: 34%
0.00141
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-601