PT-2023-31585 · Layui · Layui

Doublewrite1

+5

·

Published

2023-12-30

·

Updated

2024-01-08

·

CVE-2023-50550

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions layui versions up to v2.74
Description The issue is a cross-site scripting (XSS) vulnerability. It occurs via the data-content parameter.
Recommendations For versions up to v2.74, as a temporary workaround, consider restricting the use of the data-content parameter until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-50550
GHSA-RCVR-8WHX-3M5P

Affected Products

Layui