Описание
powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern in which text is extracted from a DOM node and interpreted as HTML.
Ссылки
- Product
- Patch
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2025-03-27 (исключая)
cpe:2.3:a:lichess:powertip.ts:*:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00057
Низкий
4.7 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 4.7
github
9 месяцев назад
powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern in which text is extracted from a DOM node and interpreted as HTML.
EPSS
Процентиль: 18%
0.00057
Низкий
4.7 Medium
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79