← العودة للجدول
CVE-2020-7741
CVE-2020-7741 — This affects the package hellojs before 1.18.6. The code get the param oauth_red
📅 2020-10-06
🔴 Critical 🔥 No NVD Exploit Web CVSS 9.9

📋 الوصف الكامل

This affects the package hellojs before 1.18.6. The code get the param oauth_redirect from url and pass it to location.assign without any check and sanitisation. So we can simply pass some XSS payloads into the url param oauth_redirect, such as javascript:alert(1).

💻 الأنظمة المتأثرة

This affects the package hellojs before

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2020-7741

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2020-7741 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←