Логотип exploitDog
bind:CVE-2024-32472
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-32472

Количество 2

Количество 2

nvd логотип

CVE-2024-32472

почти 2 года назад

excalidraw is an open source virtual hand-drawn style whiteboard. A stored XSS vulnerability in Excalidraw's web embeddable component. This allows arbitrary JavaScript to be run in the context of the domain where the editor is hosted. There were two vectors. One rendering untrusted string as iframe's `srcdoc` without properly sanitizing against HTML injection. Second by improperly sanitizing against attribute HTML injection. This in conjunction with allowing `allow-same-origin` sandbox flag (necessary for several embeds) resulted in the XSS. This vulnerability is fixed in 0.17.6 and 0.16.4.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-m64q-4jqh-f72f

почти 2 года назад

Stored Cross-site Scripting (XSS) in excalidraw's web embed component

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-32472

excalidraw is an open source virtual hand-drawn style whiteboard. A stored XSS vulnerability in Excalidraw's web embeddable component. This allows arbitrary JavaScript to be run in the context of the domain where the editor is hosted. There were two vectors. One rendering untrusted string as iframe's `srcdoc` without properly sanitizing against HTML injection. Second by improperly sanitizing against attribute HTML injection. This in conjunction with allowing `allow-same-origin` sandbox flag (necessary for several embeds) resulted in the XSS. This vulnerability is fixed in 0.17.6 and 0.16.4.

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-m64q-4jqh-f72f

Stored Cross-site Scripting (XSS) in excalidraw's web embed component

CVSS3: 6.1
0%
Низкий
почти 2 года назад

Уязвимостей на страницу