PT-2025-15235 · Unknown · Tarteaucitron.Js

Published

2025-04-07

·

Updated

2025-10-21

·

CVE-2025-31138

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions tarteaucitron.js versions prior to 1.20.1
Description A vulnerability was identified in tarteaucitron.js where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker with direct access to the site's source code or a CMS plugin to set malicious values, potentially covering the entire viewport and facilitating clickjacking attacks. An attacker with high privileges could exploit this vulnerability to overlay malicious UI elements on top of legitimate content, trick users into interacting with hidden elements, or disrupt the intended functionality and accessibility of the website.
Recommendations For versions prior to 1.20.1, update to version 1.20.1 to fix the vulnerability. As a temporary workaround, consider validating and sanitizing user-controlled inputs for element dimensions to prevent malicious values from being set. Restrict access to the CMS plugin or site's source code to minimize the risk of exploitation.

Exploit

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2025-31138
GHSA-7524-3396-FQV3

Affected Products

Tarteaucitron.Js