GHSA-fp3m-g5rc-4c28
MODERATECVE-2024-53386Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
- Affected
- <= 0.8.10
- Fixed in
- not stated
- Weakness
- CWE-79
- Published
- 2025-03-03
- Source
- github