A vulnerability, which was classified as problematic, was found in layui up to v2.8.0-rc.16. This affects an unknown part of the component HTML Attribute Handler. The manipulation of the argument title leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.8.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-234237 was assigned to this vulnerability.
History

Wed, 23 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2023-07-16T16:31:02.909Z

Updated: 2024-10-23T13:32:23.255Z

Reserved: 2023-07-15T16:34:37.981Z

Link: CVE-2023-3691

cve-icon Vulnrichment

Updated: 2024-08-02T07:01:57.392Z

cve-icon NVD

Status : Modified

Published: 2023-07-16T17:15:09.387

Modified: 2024-05-17T02:27:43.363

Link: CVE-2023-3691

cve-icon Redhat

No data.