PT-2024-21386 · Unknown · Web-Platform-Tests

Published

2024-02-26

·

Updated

2025-05-19

·

CVE-2024-26466

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions web-platform-tests/wpt versions before commit 938e843
Description A DOM based cross-site scripting (XSS) issue in the component /dom/ranges/Range-test-iframe.html allows attackers to execute arbitrary Javascript via sending a crafted URL.
Recommendations For versions before commit 938e843, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the /dom/ranges/Range-test-iframe.html component until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-26466

Affected Products

Web-Platform-Tests