6.1
CVE-2021-22540
- EPSS 0.68%
- Veröffentlicht 22.04.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:50:18
- Quelle cve-coordination@google.com
- CVE-Watchlists
- Unerledigt
XSS in Dart SDK
Bad validation logic in the Dart SDK versions prior to 2.12.3 allow an attacker to use an XSS attack via DOM clobbering. The validation logic in dart:html for creating DOM nodes from text did not sanitize properly when it came across template tags.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dart ≫ Dart Software Development Kit Version < 2.12.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.68% | 0.476 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://github.com/dart-lang/sdk/commit/ce5a1c2392debce967415d4c09359ff2555e3588
https://github.com/dart-lang/sdk/security/advisories/GHSA-3rfv-4jvg-9522