Description
We discovered a DOM Clobbering vulnerability in Webpack’s AutoPublicPathRuntimeModule. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an img tag with an unsanitized name attribute) are present.
Recommendation
Update the webpack package to the latest compatible version. Followings are version details:
- Affected version(s): >= 5.0.0-alpha.0, < 5.94.0
- Patched version(s): 5.94.0
References
Could your website be exposed too?
SmartScanner can check your website for Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS and gives you actionable findings to investigate.
Start a free scanRelated Issues
- DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS - CVE-2024-47068
- DOM Clobbering Gadget found in Rspack's AutoPublicPathRuntimeModule that leads to XSS - Vulnerability
- Layui has DOM Clobbering gadgets that leads to Cross-site Scripting - CVE-2024-47075
- DOM clobbering could escalate to Cross-site Scripting (XSS) - CVE-2024-45389


