Vulnerabilities/

DOM Clobbering Gadget found in astro's client-side router that leads to XSS

Severity:
Medium

Description

A DOM Clobbering gadget has been discoverd in Astro’s client-side router. It can lead to cross-site scripting (XSS) in websites enables Astro’s client-side routing and has stored attacker-controlled scriptless HTML elements (i.e., iframe tags with unsanitized name attributes) on the destination pages.

Recommendation

Update the astro package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
astro
Anything's wrong? Let us know Last updated on October 14, 2024

This issue is available in SmartScanner Professional

See Pricing