Логотип exploitDog
bind:CVE-2024-45047
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-45047

Количество 2

Количество 2

nvd логотип

CVE-2024-45047

больше 1 года назад

svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not including 4.2.19. Svelte improperly escapes HTML on server-side rendering. The assumption is that attributes will always stay as such, but in some situation the final DOM tree rendered on browsers is different from what Svelte expects on server-side rendering. This may be leveraged to perform XSS attacks, and a type of the XSS is known as mXSS (mutation XSS). More specifically, this can occur when injecting malicious content into an attribute within a `noscript` tag. This issue has been addressed in release version 4.2.19. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-8266-84wp-wv5c

больше 1 года назад

Svelte has a potential mXSS vulnerability due to improper HTML escaping

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-45047

svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not including 4.2.19. Svelte improperly escapes HTML on server-side rendering. The assumption is that attributes will always stay as such, but in some situation the final DOM tree rendered on browsers is different from what Svelte expects on server-side rendering. This may be leveraged to perform XSS attacks, and a type of the XSS is known as mXSS (mutation XSS). More specifically, this can occur when injecting malicious content into an attribute within a `noscript` tag. This issue has been addressed in release version 4.2.19. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-8266-84wp-wv5c

Svelte has a potential mXSS vulnerability due to improper HTML escaping

CVSS3: 5.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу