Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-34341

Опубликовано: 07 мая 2024
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Trix is a rich text editor. The Trix editor, versions prior to 2.1.1, is vulnerable to arbitrary code execution when copying and pasting content from the web or other documents with markup into the editor. The vulnerability stems from improper sanitization of pasted content, allowing an attacker to embed malicious scripts which are executed within the context of the application. Users should upgrade to Trix editor version 2.1.1 or later, which incorporates proper sanitization of input from copied content.

EPSS

Процентиль: 46%
0.00232
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
почти 2 года назад

Trix Editor Arbitrary Code Execution Vulnerability

EPSS

Процентиль: 46%
0.00232
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79