CVE-2024-47075
CVE-2024-47075: LayUI versions before 2.9.17 contain a DOM Clobbering vulnerability, potentially leading to Cross-Site Scripting (XSS) attacks. This vulnerability arises when attacker-controlled HTML elements, such as img
tags with manipulated name
attributes, are present on web pages. Successfully exploiting this flaw allows attackers to inject malicious scripts into a user's browser. Though the CVSS score is 0, indicating a base severity that might be misleading, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests a low to moderate risk, though not critical, warrants monitoring. Users of LayUI are strongly advised to upgrade to version 2.9.17 to mitigate this threat. While the SVRS isn't critical, proactive patching is essential to prevent potential XSS exploits. The presence of "In The Wild" tag suggests active exploitation attempts might be occurring, further emphasizing the need for vigilance.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.