PT-2024-21388 · Unknown · Jstrieb/Urlpages
Published
2024-02-26
·
Updated
2025-06-02
·
CVE-2024-26468
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
jstrieb/urlpages versions before commit 035b647
Description
A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages allows attackers to execute arbitrary Javascript via sending a crafted URL.
Recommendations
For versions before commit 035b647, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the index.html component to minimize the risk of exploitation.
Avoid using crafted URLs that could trigger the execution of arbitrary Javascript until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jstrieb/Urlpages