Логотип exploitDog
bind:CVE-2023-41049
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-41049

Количество 2

Количество 2

nvd логотип

CVE-2023-41049

больше 2 лет назад

@dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on version `0.1.0`. Users are advised to upgrade. Users unable to upgrade should limit untrusted user input to the `init` function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vp4f-wxgw-7x8x

больше 2 лет назад

Improper Neutralization of Script in Attributes in @dcl/single-sign-on-client

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-41049

@dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on version `0.1.0`. Users are advised to upgrade. Users unable to upgrade should limit untrusted user input to the `init` function.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-vp4f-wxgw-7x8x

Improper Neutralization of Script in Attributes in @dcl/single-sign-on-client

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу