mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
849 B
849 B
CVE-2025-1467
Description
Versions of the package tarteaucitronjs before 1.17.0 are vulnerable to Cross-site Scripting (XSS) via the getElemWidth() and getElemHeight(). This is related to SNYK-JS-TARTEAUCITRONJS-8366541
POC
Reference
- https://gist.github.com/Rudloff/d48f525215bd5426cbb076116c4422dd
- https://security.snyk.io/vuln/SNYK-JS-TARTEAUCITRONJS-8731160
Github
No PoCs found on GitHub currently.