CVE-2023-26146
29.09.2023, 05:15
All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name containing a malicious payload is served by the application, the filename is displayed without proper sanitization when it is rendered.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ithewei | libhv | * |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| ithewei\/libhv | ithewei\/libhv | 𝑥 ≤ * | ADP |