Description
LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerability that can lead to Cross-site Scripting (XSS) on web pages where attacker-controlled HTML elements (e.g., `img` tags with unsanitized `name` attributes) are present. Version 2.9.17 fixes this issue.
INFO
Published Date :
2024-09-26T17:08:19.996Z
Last Modified :
2024-09-26T18:06:22.177Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2024-47075 vulnerability.
| Vendors | Products |
|---|---|
| Layui |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-47075.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact