CVE-2022-1233
04.04.2022, 20:15
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
Vendor | Product | Version |
---|---|---|
uri.js_project | uri.js | 𝑥 < 1.19.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-115 - Misinterpretation of InputThe software misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.
- CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
References