MidnightBSD

Advisories for piqnt

CVE-2024-53386

Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cve@mitre.org 4.9 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N 1.8 2.7

Products Affected

Vendor Product Version
piqnt stage.js *