Логотип exploitDog
bind:CVE-2025-68457
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-68457

Количество 2

Количество 2

nvd логотип

CVE-2025-68457

около 2 месяцев назад

Orejime is a consent manager that focuses on accessibility. On HTML elements handled by Orejime prior to version 2.3.2, one could run malicious code by embedding `javascript:` code within data attributes. When consenting to the related purpose, Orejime would turn data attributes into unprefixed ones (i.e. `data-href` into `href`), thus executing the code. This shouldn't have any impact on most setups, as elements handled by Orejime are generally hardcoded. The problem would only arise if somebody could inject HTML code within pages. The problem has been patched in version 2.3.2. As a workaround, the problem can be fixed outside of Orejime by sanitizing attributes which could contain executable code.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-72mh-hgpm-6384

около 2 месяцев назад

Orejime has executable code in HTML attributes

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-68457

Orejime is a consent manager that focuses on accessibility. On HTML elements handled by Orejime prior to version 2.3.2, one could run malicious code by embedding `javascript:` code within data attributes. When consenting to the related purpose, Orejime would turn data attributes into unprefixed ones (i.e. `data-href` into `href`), thus executing the code. This shouldn't have any impact on most setups, as elements handled by Orejime are generally hardcoded. The problem would only arise if somebody could inject HTML code within pages. The problem has been patched in version 2.3.2. As a workaround, the problem can be fixed outside of Orejime by sanitizing attributes which could contain executable code.

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-72mh-hgpm-6384

Orejime has executable code in HTML attributes

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу