Description
Improper sanitization of the value of the [srcset] attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing .
This issue affects AngularJS versions 1.3.0-rc.4 and greater.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 1.3.0-rc.4, <= 1.8.3
References
Could your website be exposed too?
SmartScanner can check your website for AngularJS allows attackers to bypass common image source restrictions and gives you actionable findings to investigate.
Start a free scanRelated Issues
- AngularJS allows attackers to bypass common image source restrictions - angular - CVE-2024-8373
- tiny-secp256k1 allows for verify() bypass when running in bundled environment - CVE-2024-49365
- Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own server - CVE-2024-11023
- Marp Core allows XSS by improper neutralization of HTML sanitization - CVE-2024-56510


