PT-2024-32392 · Layui · Layui

Ishmeals

+1

·

Published

2024-09-26

·

Updated

2025-08-15

·

CVE-2024-47075

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions LayUI versions prior to 2.9.17
Description The issue is related to a DOM Clobbering vulnerability that can lead to Cross-site Scripting (XSS) on web pages where attacker-controlled HTML elements, such as img tags with unsanitized name attributes, are present. This vulnerability can be exploited due to the presence of unsanitized attributes in HTML elements.
Recommendations For versions prior to 2.9.17, update to version 2.9.17 to fix the issue. As a temporary workaround, consider sanitizing user-controlled input, especially attributes of HTML elements like name in img tags, to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-47075
GHSA-J827-6RGF-9629

Affected Products

Layui