PT-2018-16168 · Npm+1 · Public+1

Bl4De

+1

·

Published

2018-07-03

·

Updated

2018-10-10

·

CVE-2018-3747

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions public versions prior to 0.1.4 public versions <= 1.0.3
Description The issue allows embedding HTML in file names, which under certain conditions might lead to the execution of malicious JavaScript. This is due to the failure to sanitize filenames, enabling attackers to execute arbitrary JavaScript in the victim's browser through files with names containing malicious code.
Recommendations For public versions prior to 0.1.4, upgrade to version 0.1.4 or later. For public versions <= 1.0.3, upgrade to a version later than 1.0.3.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-3747
GHSA-8P5P-FF7X-HW7Q

Affected Products

Public
Public.Js