CVE-2023-3691
Summary
| CVE | CVE-2023-3691 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-16 17:15:00 UTC |
| Updated | 2023-11-07 04:19:00 UTC |
| Description | A vulnerability, which was classified as problematic, was found in layui up to v2.8.0-rc.16. This affects an unknown part of the component HTML Attribute Handler. The manipulation of the argument title leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.8.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-234237 was assigned to this vulnerability. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Layui | Layui | All | All | All | All |
| Application | Layui | Layui | 2.8.0 | beta1 | All | All |
| Application | Layui | Layui | 2.8.0 | beta2 | All | All |
| Application | Layui | Layui | 2.8.0 | beta3 | All | All |
| Application | Layui | Layui | 2.8.0 | rc1 | All | All |
| Application | Layui | Layui | 2.8.0 | rc10 | All | All |
| Application | Layui | Layui | 2.8.0 | rc11 | All | All |
| Application | Layui | Layui | 2.8.0 | rc12 | All | All |
| Application | Layui | Layui | 2.8.0 | rc13 | All | All |
| Application | Layui | Layui | 2.8.0 | rc14 | All | All |
| Application | Layui | Layui | 2.8.0 | rc15 | All | All |
| Application | Layui | Layui | 2.8.0 | rc16 | All | All |
| Application | Layui | Layui | 2.8.0 | rc2 | All | All |
| Application | Layui | Layui | 2.8.0 | rc3 | All | All |
| Application | Layui | Layui | 2.8.0 | rc4 | All | All |
| Application | Layui | Layui | 2.8.0 | rc5 | All | All |
| Application | Layui | Layui | 2.8.0 | rc6 | All | All |
| Application | Layui | Layui | 2.8.0 | rc7 | All | All |
| Application | Layui | Layui | 2.8.0 | rc8 | All | All |
| Application | Layui | Layui | 2.8.0 | rc9 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| checkbox等title渲染时有xss · Issue #I7HDXZ · Layui/layui - Gitee.com | MISC | gitee.com | |
| Login required | MISC | vuldb.com | |
| CVE-2023-3691: layui HTML Attribute cross site scripting (I7HDXZ) | MISC | vuldb.com | |
| layui: 一套遵循原生态开发模式的 Web UI 组件库,采用自身轻量级模块化规范,极易上手,可以更简单快速地构建网页界面。 - Gitee.com | MISC | gitee.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.