Описание
Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user input which allows an attacker to execute malicious javascript on anyone viewing a malicious quote submission. quote.text and quote.source are user input, and they're inserted straight into the DOM. If they contain HTML tags, they will be rendered (after some escaping using quotes and textarea tags).
Ссылки
- Patch
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 25.49.0 (включая)
cpe:2.3:a:monkeytype:monkeytype:*:*:*:*:*:*:*:*
EPSS
Процентиль: 14%
0.00045
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
EPSS
Процентиль: 14%
0.00045
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79