Количество 2
Количество 2

CVE-2021-35440
Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS). A URL for a widget can be crafted and used to execute JavaScript on the victim's computer. The JavaScript code can then steal data available in the session/cookies depending on the user environment (e.g. if re-using internal URL's for deploying, or cookies that are very permissive) private information may be retrieved by the attacker.
GHSA-254j-mmc5-qhpx
Smashing Cross-site Scripting vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2021-35440 Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS). A URL for a widget can be crafted and used to execute JavaScript on the victim's computer. The JavaScript code can then steal data available in the session/cookies depending on the user environment (e.g. if re-using internal URL's for deploying, or cookies that are very permissive) private information may be retrieved by the attacker. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад |
GHSA-254j-mmc5-qhpx Smashing Cross-site Scripting vulnerability | CVSS3: 6.1 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу