Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-47885

Опубликовано: 14 окт. 2024
Источник: nvd
CVSS3: 5.9
CVSS3: 5.4
EPSS Низкий

Описание

The Astro web framework has a DOM Clobbering gadget in the client-side router starting in version 3.0.0 and prior to version 4.16.1. It can lead to cross-site scripting (XSS) in websites enables Astro's client-side routing and has stored attacker-controlled scriptless HTML elements (i.e., iframe tags with unsanitized name attributes) on the destination pages. This vulnerability can result in cross-site scripting (XSS) attacks on websites that built with Astro that enable the client-side routing with ViewTransitions and store the user-inserted scriptless HTML tags without properly sanitizing the name attributes on the page. Version 4.16.1 contains a patch for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:astro:astro:*:*:*:*:*:node.js:*:*
Версия от 3.0.0 (включая) до 4.16.1 (исключая)

EPSS

Процентиль: 71%
0.00694
Низкий

5.9 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.9
github
больше 1 года назад

DOM Clobbering Gadget found in astro's client-side router that leads to XSS

EPSS

Процентиль: 71%
0.00694
Низкий

5.9 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79