PT-2021-24349 · Unknown · Molecularfaces

Published

2021-04-16

·

Updated

2025-11-28

·

CVE-2024-0758

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: MolecularFaces versions prior to 0.3.0
Description: The issue allows a remote attacker to execute arbitrary JavaScript in the context of a victim browser via crafted molfiles. This is due to the viewer plugin implementation of <mol:molecule> rendering molfile data directly inside a <script> tag without any escaping, allowing arbitrary JavaScript code to be executed in the client browser.
Recommendations: For versions prior to 0.3.0, update to version 0.3.0 or later, where molfile data is now rendered as the value of a hidden <input> tag and escaped via JSF's mechanisms. As a temporary workaround, consider restricting the use of crafted molfiles until a patch is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-0758
GHSA-2PWH-52H7-7J84
GHSA-WC6F-QJXC-622V

Affected Products

Molecularfaces