Lucene search

K
osvGoogleOSV:CVE-2024-47075
HistorySep 26, 2024 - 6:15 p.m.

CVE-2024-47075

2024-09-2618:15:08
Google
osv.dev
2
layui
dom clobbering
xss
vulnerability
cve-2024-47075

CVSS3

6.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.6%

LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerability that can lead to Cross-site Scripting (XSS) on web pages where attacker-controlled HTML elements (e.g., img tags with unsanitized name attributes) are present. Version 2.9.17 fixes this issue.

CVSS3

6.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.6%

Related for OSV:CVE-2024-47075