Description

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .

INFO

Published Date :

2024-09-09T14:46:03.134Z

Last Modified :

2025-11-03T19:34:58.181Z

Source :

HeroDevs
AFFECTED PRODUCTS

The following products are affected by CVE-2024-8372 vulnerability.

Vendors Products
Angularjs
  • Angular.js
  • Angularjs
Netapp
  • Active Iq Unified Manager

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact