Description
Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-35154 | Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources. |
References
| Link | Providers |
|---|---|
| https://github.com/facebook/lexical/releases/tag/v0.10.0 |
|
History
Thu, 30 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2025-01-30T17:07:21.811Z
Reserved: 2023-04-17T13:42:08.187Z
Link: CVE-2023-30792
Updated: 2024-08-02T14:37:15.458Z
Status : Modified
Published: 2023-04-29T03:15:08.347
Modified: 2025-01-30T17:15:16.647
Link: CVE-2023-30792
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD