Lucene search

K
osvGoogleOSV:CVE-2023-30792
HistoryApr 29, 2023 - 3:15 a.m.

CVE-2023-30792

2023-04-2903:15:08
Google
osv.dev
2
cross-site scripting
anchor tag
untrusted input
security vulnerability
software

6.4 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.4%

Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources.

6.4 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.4%

Related for OSV:CVE-2023-30792