PT-2024-38977 · Angularjs+3 · Angularjs+3

George Kalpakas

·

Published

2024-05-21

·

Updated

2026-01-14

·

CVE-2024-8372

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions: AngularJS versions 1.3.0-rc.4 and greater
Description: The issue is due to improper sanitization of the value of the [srcset] attribute in AngularJS, allowing attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing. The AngularJS project is End-of-Life and will not receive any updates to address this issue.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2025-02357
CVE-2024-8372
DLA-4242-1
GHSA-M9GF-397R-HWPG
USN-7958-1

Affected Products

Angularjs
Debian
Linuxmint
Ubuntu