Логотип exploitDog
bind:CVE-2024-34341
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-34341

Количество 2

Количество 2

nvd логотип

CVE-2024-34341

почти 2 года назад

Trix is a rich text editor. The Trix editor, versions prior to 2.1.1, is vulnerable to arbitrary code execution when copying and pasting content from the web or other documents with markup into the editor. The vulnerability stems from improper sanitization of pasted content, allowing an attacker to embed malicious scripts which are executed within the context of the application. Users should upgrade to Trix editor version 2.1.1 or later, which incorporates proper sanitization of input from copied content.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-qjqp-xr96-cj99

почти 2 года назад

Trix Editor Arbitrary Code Execution Vulnerability

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-34341

Trix is a rich text editor. The Trix editor, versions prior to 2.1.1, is vulnerable to arbitrary code execution when copying and pasting content from the web or other documents with markup into the editor. The vulnerability stems from improper sanitization of pasted content, allowing an attacker to embed malicious scripts which are executed within the context of the application. Users should upgrade to Trix editor version 2.1.1 or later, which incorporates proper sanitization of input from copied content.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-qjqp-xr96-cj99

Trix Editor Arbitrary Code Execution Vulnerability

CVSS3: 5.4
0%
Низкий
почти 2 года назад

Уязвимостей на страницу