Description
All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name containing a malicious payload is served by the application, the filename is displayed without proper sanitization when it is rendered.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29981 | All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name containing a malicious payload is served by the application, the filename is displayed without proper sanitization when it is rendered. |
References
History
Mon, 23 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ithewei\/libhv
Ithewei\/libhv ithewei\/libhv |
|
| CPEs | cpe:2.3:a:ithewei\/libhv:ithewei\/libhv:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ithewei\/libhv
Ithewei\/libhv ithewei\/libhv |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-23T16:30:04.213Z
Reserved: 2023-02-20T10:28:48.929Z
Link: CVE-2023-26146
Updated: 2024-08-02T11:39:06.566Z
Status : Modified
Published: 2023-09-29T05:15:46.540
Modified: 2024-11-21T07:50:52.447
Link: CVE-2023-26146
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD