Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53973 | Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements. |
Github GHSA |
GHSA-x7hr-w5r2-h6wg | PrismJS DOM Clobbering vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 27 Jun 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prismjs
Prismjs prism |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:prismjs:prism:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Prismjs
Prismjs prism |
Wed, 12 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | prismjs: DOM Clobbering vulnerability within the Prism library's prism-autoloader plugin | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Mar 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements. | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-03T21:53:33.210Z
Reserved: 2024-11-20T00:00:00.000Z
Link: CVE-2024-53382
Updated: 2025-03-03T21:53:13.145Z
Status : Analyzed
Published: 2025-03-03T07:15:33.397
Modified: 2025-06-27T13:08:24.660
Link: CVE-2024-53382
OpenCVE Enrichment
No data.
EUVD
Github GHSA