Количество 2
Количество 2
CVE-2024-53386
11 месяцев назад
Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
CVSS3: 4.9
EPSS: Низкий
GHSA-fp3m-g5rc-4c28
11 месяцев назад
Stage.js DOM Clobbering vulnerabilty
CVSS3: 4.9
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-53386 Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements. | CVSS3: 4.9 | 0% Низкий | 11 месяцев назад | |
GHSA-fp3m-g5rc-4c28 Stage.js DOM Clobbering vulnerabilty | CVSS3: 4.9 | 0% Низкий | 11 месяцев назад |
Уязвимостей на страницу
20