MEDIUM
RelaxedJS ReLaXed Pug to PDF Converter cross site scripting
Published Sep 27, 2024
4.8
MEDIUMCVSS 4.0
EPSS 0.27%
Description
A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF Converter. The manipulation leads to cross site scripting. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 0.2.0StatusaffectedConstraints-
- Version 0.2.1StatusaffectedConstraints-
- Version 0.2.2StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
relaxedjs
npm
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | relaxedjs | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://drive.google.com/file/d/1Ll1dRwQds8987S-l5o2iJu4MQRG-p4-A/view?usp=sharing exploit
- https://github.com/advisories/GHSA-gj3p-j74v-3x57 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-9283
- https://vuldb.com/?ctiid.278676 signaturepermissions-required
- https://vuldb.com/?id.278676 vdb-entry
- https://vuldb.com/?submit.411185 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://drive.google.com/file/d/1Ll1dRwQds8987S-l5o2iJu4MQRG-p4-A/view?usp=sharing | exploit | |
| https://github.com/advisories/GHSA-gj3p-j74v-3x57 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-9283 | ||
| https://vuldb.com/?ctiid.278676 | signaturepermissions-required | |
| https://vuldb.com/?id.278676 | vdb-entry | |
| https://vuldb.com/?submit.411185 | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 27, 2024
Updated Sep 27, 2024
Reserved Sep 27, 2024
Link CVE-2024-9283
CISA Vulnrichment
GHSA-GJ3P-J74V-3X57 Updated Sep 27, 2024