Description

LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerability that can lead to Cross-site Scripting (XSS) on web pages where attacker-controlled HTML elements (e.g., `img` tags with unsanitized `name` attributes) are present. Version 2.9.17 fixes this issue.

INFO

Published Date :

2024-09-26T17:08:19.996Z

Last Modified :

2024-09-26T18:06:22.177Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-47075 vulnerability.

Vendors Products
Layui
  • Layui
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-47075.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact