CVE-2023-3672

Cross-site Scripting (XSS) - DOM in GitHub repository plaidweb/webmention.js prior to 0.5.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:plaidweb:webmention.js:*:*:*:*:*:*:*:*

History

25 Jul 2023, 18:17

Type Values Removed Values Added
References (MISC) https://huntr.dev/bounties/75cfb7ad-a75f-45ff-8688-32a9c55179aa - (MISC) https://huntr.dev/bounties/75cfb7ad-a75f-45ff-8688-32a9c55179aa - Exploit, Third Party Advisory
References (MISC) https://github.com/plaidweb/webmention.js/commit/3551b66b3e40da37fee89ecf72930c5efdc53011 - (MISC) https://github.com/plaidweb/webmention.js/commit/3551b66b3e40da37fee89ecf72930c5efdc53011 - Patch
First Time Plaidweb
Plaidweb webmention.js
CPE cpe:2.3:a:plaidweb:webmention.js:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

14 Jul 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-14 10:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-3672

Mitre link : CVE-2023-3672

CVE.ORG link : CVE-2023-3672


JSON object : View

Products Affected

plaidweb

  • webmention.js
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')