PT-2024-32392 · Layui · Layui
Ishmeals
+1
·
Published
2024-09-26
·
Updated
2025-08-15
·
CVE-2024-47075
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
LayUI versions prior to 2.9.17
Description
The issue is related to a DOM Clobbering vulnerability that can lead to Cross-site Scripting (XSS) on web pages where attacker-controlled HTML elements, such as
img tags with unsanitized name attributes, are present. This vulnerability can be exploited due to the presence of unsanitized attributes in HTML elements.Recommendations
For versions prior to 2.9.17, update to version 2.9.17 to fix the issue. As a temporary workaround, consider sanitizing user-controlled input, especially attributes of HTML elements like
name in img tags, to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Layui