Логотип exploitDog
bind:CVE-2024-53382
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-53382

Количество 5

Количество 5

ubuntu логотип

CVE-2024-53382

10 месяцев назад

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2024-53382

10 месяцев назад

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2024-53382

10 месяцев назад

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2024-53382

10 месяцев назад

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resulta ...

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-x7hr-w5r2-h6wg

10 месяцев назад

PrismJS DOM Clobbering vulnerability

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-53382

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

CVSS3: 4.9
0%
Низкий
10 месяцев назад
redhat логотип
CVE-2024-53382

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

CVSS3: 4.9
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-53382

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

CVSS3: 4.9
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-53382

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resulta ...

CVSS3: 4.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-x7hr-w5r2-h6wg

PrismJS DOM Clobbering vulnerability

CVSS3: 4.9
0%
Низкий
10 месяцев назад

Уязвимостей на страницу