cve/2018/CVE-2018-6341.md

22 lines
1.1 KiB
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2018-6341](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6341)
![](https://img.shields.io/static/v1?label=Product&message=react-dom&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=!%3D%3E%2016.4.2%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Improper%20Neutralization%20of%20Input%20During%20Web%20Page%20Generation%20(CWE-79)&color=brighgreen)
### Description
React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/JCDMeira/release-notes-react
- https://github.com/diwangs/react16-ssr
- https://github.com/freeshineit/react-changelog
- https://github.com/msgre/scratch3
- https://github.com/ossf-cve-benchmark/CVE-2018-6341