All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name containing a malicious payload is served by the application, the filename is displayed without proper sanitization when it is rendered.
History

Mon, 23 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Ithewei\/libhv
Ithewei\/libhv ithewei\/libhv
CPEs cpe:2.3:a:ithewei\/libhv:ithewei\/libhv:*:*:*:*:*:*:*:*
Vendors & Products Ithewei\/libhv
Ithewei\/libhv ithewei\/libhv
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2023-09-29T05:00:01.401Z

Updated: 2024-09-23T16:30:04.213Z

Reserved: 2023-02-20T10:28:48.929Z

Link: CVE-2023-26146

cve-icon Vulnrichment

Updated: 2024-08-02T11:39:06.566Z

cve-icon NVD

Status : Modified

Published: 2023-09-29T05:15:46.540

Modified: 2024-11-21T07:50:52.447

Link: CVE-2023-26146

cve-icon Redhat

No data.