6.1

CVE-2023-3691

Exploit

layui HTML Attribute cross site scripting

A vulnerability, which was classified as problematic, was found in layui up to v2.8.0-rc.16. This affects an unknown part of the component HTML Attribute Handler. The manipulation of the argument title leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.8.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-234237 was assigned to this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Layui ≫ Layui Version < 2.8.0
Layui ≫ Layui Version 2.8.0 Update beta1
Layui ≫ Layui Version 2.8.0 Update beta2
Layui ≫ Layui Version 2.8.0 Update beta3
Layui ≫ Layui Version 2.8.0 Update rc1
Layui ≫ Layui Version 2.8.0 Update rc10
Layui ≫ Layui Version 2.8.0 Update rc11
Layui ≫ Layui Version 2.8.0 Update rc12
Layui ≫ Layui Version 2.8.0 Update rc13
Layui ≫ Layui Version 2.8.0 Update rc14
Layui ≫ Layui Version 2.8.0 Update rc15
Layui ≫ Layui Version 2.8.0 Update rc16
Layui ≫ Layui Version 2.8.0 Update rc2
Layui ≫ Layui Version 2.8.0 Update rc3
Layui ≫ Layui Version 2.8.0 Update rc4
Layui ≫ Layui Version 2.8.0 Update rc5
Layui ≫ Layui Version 2.8.0 Update rc6
Layui ≫ Layui Version 2.8.0 Update rc7
Layui ≫ Layui Version 2.8.0 Update rc8
Layui ≫ Layui Version 2.8.0 Update rc9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.415
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cna@vuldb.com 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
cna@vuldb.com 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://gitee.com/layui/layui/issues/I7HDXZ
Third Party Advisory
Exploit
Issue Tracking
https://gitee.com/layui/layui/tree/v2.8.0
Product
https://vuldb.com/?ctiid.234237
Third Party Advisory
https://vuldb.com/?id.234237
Third Party Advisory