icon

We found results for “

WS-2020-0093

Good to know:

icon
icon

Date: May 20, 2020

lazysizes before 5.2.1-rc1 are vulnerable to Cross-Site Scripting. The video-embed plugin fails to sanitize the following attributes: data-vimeo, data-vimeoparams, data-youtube and data-ytparams. This allows attackers to execute arbitrary JavaScript in a victim's browser if the attacker has control over the vulnerable attributes.

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-78

Top Fix

icon

Upgrade Version

Upgrade to version bpocallaghan/laravel-admin-starter - no_fix;bpocallaghan/laravel-admin-starter - dev-Laravel_5.2;bpocallaghan/laravel-admin-starter - dev-Laravel_5.4;bpocallaghan/laravel-admin-starter - dev-dependabot/npm_and_yarn/eventsource-1.1.1;bpocallaghan/laravel-admin-starter - dev-dependabot/npm_and_yarn/loader-utils-1.4.2;bpocallaghan/laravel-admin-starter - dev-dependabot/npm_and_yarn/ajv-6.12.6;bpocallaghan/laravel-admin-starter - dev-dependabot/npm_and_yarn/url-parse-1.5.7;bpocallaghan/laravel-admin-starter - dev-dependabot/npm_and_yarn/tar-4.4.19;bpocallaghan/laravel-admin-starter - dev-dependabot/npm_and_yarn/follow-redirects-1.14.7;bpocallaghan/laravel-admin-starter - 0.0.1;bpocallaghan/laravel-admin-starter - v2.x-dev;bpocallaghan/laravel-admin-starter - dev-dependabot/npm_and_yarn/minimatch-3.1.2;bpocallaghan/laravel-admin-starter - 1.0.1;tollwerk/tw-base - v1.0.0;tollwerk/tw-base - v4.7.0;tollwerk/tw-base - dev-typo3-9;madhouse/craft-starter - 1.0.10;madhouse/craft-starter - dev-andrewmenich-patch-1;madhouse/craft-starter - 1.0.3;woody-wordpress/woody-theme - dev-hideDraftPostsInMenu;woody-wordpress/woody-theme - dev-addHeroTitlesToPrintVersion;woody-wordpress/woody-theme - dev-mirrorPageBreadcrumb;woody-wordpress/woody-theme - dev-feature/bookblock-texts;woody-wordpress/woody-theme - dev-Feature/jQuery3.6.0;woody-wordpress/woody-theme - dev-bugfix/mirrorPagePreview;woody-wordpress/woody-theme - dev-newHawwwaiSheet;woody-wordpress/woody-theme - dev-bugfix/createdFrom-function;woody-wordpress/woody-theme - dev-feature/responsiveOptions;woody-wordpress/woody-theme - dev-feature/pageTeaser07MapButtonClose;woody-wordpress/woody-theme - dev-feature/rollBackPostCreatedBehaviour;woody-wordpress/woody-theme - 1.1.0;woody-wordpress/woody-theme - dev-feature/translateNL_BE;woody-wordpress/woody-theme - dev-feature/getPagePreviewJs;woody-wordpress/woody-theme - dev-feature/addBadgeForNewWoodyTpls;woody-wordpress/woody-theme - dev-feature/moreTouristInformations;woody-wordpress/woody-theme - dev-feature/woody-animations;woody-wordpress/woody-theme - dev-feature/CleanupRewriteRules;woody-wordpress/woody-theme - dev-feature/AddonCookies;woody-wordpress/woody-theme - dev-feature/addFilterLazyImgLandswprSlide;woody-wordpress/woody-theme - dev-feature/pageTeaserBgMoreData;woody-wordpress/woody-theme - dev-bugfix/unpublish;woody-wordpress/woody-theme - dev-feature/traduction;woody-wordpress/woody-theme - dev-feature/createdPostsDate;woody-wordpress/woody-theme - dev-feature/mixtGallery;woody-wordpress/woody-theme - dev-feature/addNewRuleRobotsTxt;woody-wordpress/woody-theme - dev-feature/EsSearchV2;woody-wordpress/woody-theme - dev-bugfix/sessionExpiration;woody-wordpress/woody-theme - dev-feature/TplPopin;woody-wordpress/woody-theme - dev-feature/sitemap-inc;woody-wordpress/woody-theme - dev-feature/mapsKeys;woody-wordpress/woody-theme - dev-fix/auto-focus-menu-order;woody-wordpress/woody-theme - dev-addWiconClassToPageTerms;woody-wordpress/woody-theme - dev-feature/addMoreContextTools;woody-wordpress/woody-theme - dev-feature/default-tm-conf;woody-wordpress/woody-theme - dev-fix/landing-swipers-button;woody-wordpress/woody-theme - dev-feature/allow-opacity-bg-params;woody-wordpress/woody-theme - dev-feature/addResponsiveOptions;woody-wordpress/woody-theme - dev-displayParentTagName;woody-wordpress/woody-theme - dev-fix/teaserTitle;woody-wordpress/woody-theme - dev-feature/improveAccessibility;woody-wordpress/woody-theme - dev-feature/topicsEnhanced;woody-wordpress/woody-theme - dev-addLinkedInShare;woody-wordpress/woody-theme - dev-feature/convertShortcodeToBlocs;woody-wordpress/woody-theme - dev-feature/addTablePluginTinyMCE;woody-wordpress/woody-theme - dev-feature/newSheetUpdate;woody-wordpress/woody-theme - dev-feature/updatePrintCss;woody-wordpress/woody-theme - dev-feature/displayAnchorIndexInSummary;woody-wordpress/woody-theme - dev-feature/humanizeSheetTitleBreadcrumb;woody-wordpress/woody-theme - dev-feature/addLabelPublicationDate;woody-wordpress/woody-theme - dev-feature/profileCustomPostType;woody-wordpress/woody-theme - dev-show-sharing-links-on-click;woody-wordpress/woody-theme - dev-feature/feature/primaryBtnVar;woody-wordpress/woody-theme - dev-feature/improveResponsiveOrderWording;woody-wordpress/woody-theme - dev-feature/addon-thumbnails;woody-wordpress/woody-theme - dev-feature/addCookieIconForCookiesBannerResponsive;woody-wordpress/woody-theme - dev-feature/sectionClasses;woody-wordpress/woody-theme - dev-feature/addPinnableContent;woody-wordpress/woody-theme - dev-loadBlocksCloneLatre;woody-wordpress/woody-theme - dev-feature/faq-to-groups;woody-wordpress/woody-theme - dev-feature/pwaHowTo;woody-wordpress/woody-theme - dev-fix/cta-and-text-padding;woody-wordpress/woody-theme - dev-feature/drag-and-drop;woody-wordpress/woody-theme - dev-feature/add-alignement-choice-tabs-block;woody-wordpress/woody-theme - dev-feature/MetaLangUsage;woody-wordpress/woody-theme - dev-Feature/phpmailer;woody-wordpress/woody-theme - dev-feature/theRoadBook;woody-wordpress/woody-theme - dev-feature/woodyseo_canonical_url;woody-wordpress/woody-theme - dev-feature/GeoJSONMea;woody-wordpress/woody-theme - dev-feature/RedirectPermalink;woody-wordpress/woody-theme - dev-feature/TouristicMapV2;woody-wordpress/woody-theme - dev-feature/bloc-titles;bpocallaghan/titan - 1.0.4;bpocallaghan/titan - 1.0.9;bpocallaghan/titan - 1.0.2;bpocallaghan/titan - dev-dependabot/npm_and_yarn/resources/assets_setup/ajv-6.12.6;bpocallaghan/titan - dev-dependabot/npm_and_yarn/resources/assets_setup/eventsource-1.1.1;bpocallaghan/titan - dev-L5.2;bpocallaghan/titan - no_fix;bpocallaghan/titan - dev-dependabot/npm_and_yarn/resources/assets_setup/tar-4.4.19;bpocallaghan/titan - dev-dependabot/npm_and_yarn/resources/assets_setup/follow-redirects-1.14.7;bpocallaghan/titan - 1.2.7;bpocallaghan/titan - dev-dependabot/npm_and_yarn/resources/assets_setup/minimatch-3.1.2;bpocallaghan/titan - dev-utils;bpocallaghan/titan - dev-dependabot/npm_and_yarn/resources/assets_setup/loader-utils-1.4.2;bpocallaghan/titan - dev-dependabot/npm_and_yarn/resources/assets_setup/url-parse-1.5.7;bpocallaghan/titan - 1.2.1;pressgang-wp/pressgang - dev-dependabot/npm_and_yarn/bl-1.2.3;pressgang-wp/pressgang - no_fix;pressgang-wp/pressgang - v1.x-dev;pressgang-wp/pressgang - dev-test;pressgang-wp/pressgang - dev-master;pressgang-wp/pressgang - dev-dependabot/npm_and_yarn/mixin-deep-1.3.2;pressgang-wp/pressgang - dev-timber-v2;x-cart-proj/x-cart-proj - no_fix;visol/viresponsiveimages - no_fix;visol/viresponsiveimages - 0.9.14;derhaeuptling/contao-lazy-images - 3.0.4;derhaeuptling/contao-lazy-images - no_fix;derhaeuptling/contao-lazy-images - 1.0.3;derhaeuptling/contao-lazy-images - 3.0.7;Our.Umbraco.Slimsy - 2.0.0-beta4;Our.Umbraco.Slimsy - 3.0.0-beta4;benedict-w/pressgang - no_fix;voidagency/vactory-project - 1.1.0;voidagency/vactory-project - dev-dependabot/bundler/capistrano/rake-13.0.1;webgene/webgene-project - no_fix;dnadesign/silverstripe-lazyloaded-image - 0.1.0;dnadesign/silverstripe-lazyloaded-image - 0.3.0;dnadesign/silverstripe-lazyloaded-image - no_fix;dawehner/lazysizes - no_fix;davyin/dyniva_ui - dev-3.x-esbuild;davyin/dyniva_ui - 2.1.x-dev;davyin/dyniva_ui - dev-1.x-dev-lzy;simplon/component_mvc - 0.0.1;simplon/component_mvc - no_fix;hadwao/image-inliner - no_fix;gregleveque/ez-progressive-image-bundle - no_fix;pi/pi - v2.8.0;pi/pi - no_fix;pi/pi - v2.5.0-alpha1;lazysizes - 5.2.1;etdsolutions/lazysizes - no_fix;chibko/contao-bootstrap - no_fix;LittleNorth.Igloo - 5.0.4-rc.1;brunocfalcao/laraflash-website - no_fix;org.webjars.bower:lazysizes:1.4.0;org.webjars.bower:lazysizes:1.3.1;org.webjars.bower:lazysizes:5.1.2;org.webjars.npm:lazysizes:no_fix

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us