Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-69993

Опубликовано: 14 апр. 2026
Источник: redhat
CVSS3: 6.1

Описание

Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., ). When a victim views an affected map popup, the malicious script executes in the context of the victim's browser session.

A flaw was found in Leaflet. This Cross-Site Scripting (XSS) vulnerability exists in the bindPopup() method, which fails to sanitize user-supplied input. A remote attacker can exploit this by injecting malicious JavaScript code into map popups. When a victim views an affected map, the injected script executes in their browser, potentially leading to information disclosure or other client-side attacks.

Отчет

There's a Moderate severity flaw in the bindPopup() method in Leaflet does not sanitize user-supplied input, allowing an attacker to inject malicious JavaScript. If the application accepts an user controlled input further used by Leaflet the attacker may inject raw HTML tags, achieving a stored XSS attack.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-mlflow-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2458210Leaflet: Leaflet: Cross-Site Scripting (XSS) via unsanitized input in bindPopup() method

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
4 месяца назад

Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., <img src=x onerror="alert('XSS')">). When a victim views an affected map popup, the malicious script executes in the context of the victim's browser session.

CVSS3: 6.1
nvd
4 месяца назад

Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., <img src=x onerror="alert('XSS')">). When a victim views an affected map popup, the malicious script executes in the context of the victim's browser session.

CVSS3: 6.1
debian
4 месяца назад

Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Sit ...

CVSS3: 6.1
github
4 месяца назад

Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., <img src=x onerror="alert('XSS')">). When a victim views an affected map popup, the malicious script executes in the context of the victim's browser session.

6.1 Medium

CVSS3