Логотип exploitDog
bind:CVE-2022-25875
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-25875

Количество 2

Количество 2

nvd логотип

CVE-2022-25875

больше 3 лет назад

The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-wv8q-r932-8hc7

больше 3 лет назад

Svelte vulnerable to XSS when using objects during server-side rendering

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-25875

The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-wv8q-r932-8hc7

Svelte vulnerable to XSS when using objects during server-side rendering

CVSS3: 6.1
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу