Description
Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
Published: 2025-03-03
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-53972 Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
Github GHSA Github GHSA GHSA-fp3m-g5rc-4c28 Stage.js DOM Clobbering vulnerabilty
History

Fri, 27 Jun 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Piqnt
Piqnt stage.js
Weaknesses CWE-79
CPEs cpe:2.3:a:piqnt:stage.js:*:*:*:*:*:*:*:*
Vendors & Products Piqnt
Piqnt stage.js

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 06:30:00 +0000

Type Values Removed Values Added
Description Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-03T21:55:00.596Z

Reserved: 2024-11-20T00:00:00.000Z

Link: CVE-2024-53386

cve-icon Vulnrichment

Updated: 2025-03-03T21:54:44.292Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-03T07:15:34.560

Modified: 2025-06-27T13:01:00.597

Link: CVE-2024-53386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses