angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor indicates that there is no documentation indicating that a key is supposed to be safe against XSS attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-04-26T00:00:00
Updated: 2024-10-29T20:43:15.458Z
Reserved: 2024-04-26T00:00:00
Link: CVE-2024-33665
Vulnrichment
Updated: 2024-08-02T02:36:04.467Z
NVD
Status : Awaiting Analysis
Published: 2024-04-26T01:15:46.100
Modified: 2024-10-29T21:35:08.080
Link: CVE-2024-33665
Redhat
No data.