CVE-2024-53386 - CERT CVE
ID CVE-2024-53386
Sažetak Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
Reference
CVSS
Base: 4.9
Impact: 2.7
Exploitability:1.8
Pristup
VektorSloženostAutentikacija
NETWORK HIGH LOW
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW NONE
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Zadnje važnije ažuriranje 03-03-2025 - 22:15
Objavljeno 03-03-2025 - 07:15