CVE-2024-8373

Sept. 9, 2024, 6:30 p.m.

Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

AngularJS

Source

36c7be3b-2937-45df-85ea-ca7133ea542c

Tags

CVE-2024-8373 details

Published : Sept. 9, 2024, 3:15 p.m.
Last Modified : Sept. 9, 2024, 6:30 p.m.

Description

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

CVSS Score

1 2 3 4.8 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-791 Incomplete Filtering of Special Elements The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.

CVSS Data

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

Base Score

4.8

Exploitability Score

2.2

Impact Score

2.5

Base Severity

MEDIUM

References

URL Source
https://codepen.io/herodevs/full/bGPQgMp/8da9ce87e99403ee13a295c305ebfa0b 36c7be3b-2937-45df-85ea-ca7133ea542c
https://www.herodevs.com/vulnerability-directory/cve-2024-8373 36c7be3b-2937-45df-85ea-ca7133ea542c
This website uses the NVD API, but is not approved or certified by it.