Логотип exploitDog
bind:CVE-2022-25349
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-25349

Количество 3

Количество 3

nvd логотип

CVE-2022-25349

почти 4 года назад

All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-25349

почти 4 года назад

All versions of package materialize-css are vulnerable to Cross-site S ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-7jvx-f994-rfw2

почти 4 года назад

materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-25349

All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-25349

All versions of package materialize-css are vulnerable to Cross-site S ...

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-7jvx-f994-rfw2

materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input

CVSS3: 5.4
0%
Низкий
почти 4 года назад

Уязвимостей на страницу