PT-2025-36908 · Unknown · Elements Plus!

Snowbitx

·

Publicado

2025-09-09

·

Atualizado

2025-09-10

·

CVE-2025-57665

CVSS v4.0

6.6

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions: Element Plus versions through 2.10.6
Description: The Element Plus Link component (el-link) does not sufficiently validate input for the href attribute, creating a security gap. This allows attackers to inject malicious URLs using dangerous protocols (such as javascript:, data:, and file:) or redirect users to malicious sites. This enables cross-site scripting (XSS) attacks, phishing campaigns, and open redirect exploits in applications using the component with user-controlled or untrusted URL inputs.
Recommendations: Element Plus versions prior to 2.10.6 are affected. Ensure proper validation and sanitization of the href attribute before using it in the Link component. Implement security headers to mitigate potential risks associated with user-controlled URLs.

Correção

Open Redirect

XSS

Improper Encoding or Escaping of Output

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-57665
GHSA-5M5X-9J46-H678

Produtos afetados

Elements Plus!