Description

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

INFO

Published Date :

2025-03-03T00:00:00.000Z

Last Modified :

2025-03-03T21:53:33.210Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-53382 vulnerability.

Vendors Products
Prismjs
  • Prism

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact