Description
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1341 | The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. |
Github GHSA |
GHSA-6c9x-mj3g-h47x | Spoofing attack in swagger-ui-dist |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T05:17:41.728Z
Reserved: 2022-03-11T00:00:00.000Z
Link: CVE-2021-46708
No data.
Status : Modified
Published: 2022-03-11T07:15:07.927
Modified: 2024-11-21T06:34:36.543
Link: CVE-2021-46708
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA