PT-2025-15235 · Unknown · Tarteaucitron.Js
Published
2025-04-07
·
Updated
2025-10-21
·
CVE-2025-31138
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
tarteaucitron.js versions prior to 1.20.1
Description
A vulnerability was identified in tarteaucitron.js where user-controlled inputs for element dimensions (
width and height) were not properly validated. This allowed an attacker with direct access to the site's source code or a CMS plugin to set malicious values, potentially covering the entire viewport and facilitating clickjacking attacks. An attacker with high privileges could exploit this vulnerability to overlay malicious UI elements on top of legitimate content, trick users into interacting with hidden elements, or disrupt the intended functionality and accessibility of the website.Recommendations
For versions prior to 1.20.1, update to version 1.20.1 to fix the vulnerability. As a temporary workaround, consider validating and sanitizing user-controlled inputs for element dimensions to prevent malicious values from being set. Restrict access to the CMS plugin or site's source code to minimize the risk of exploitation.
Exploit
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tarteaucitron.Js