PT-2019-12748 · Shave · Shave

Digitalcraft

·

Publicado

2019-05-24

·

Atualizado

2019-05-29

·

CVE-2019-12313

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Shave versions prior to 2.5.3
Description The issue exists due to mishandled output encoding during the overwrite of an HTML element, which can lead to Cross-Site Scripting. If encoded HTML input is passed into the shave package, the output will be decoded, potentially resulting in Cross-Site Scripting.
Recommendations Upgrade to version 2.5.3 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12313
GHSA-GH4G-3GM9-5WRQ

Produtos afetados

Shave