CVE-2024-26467
26.02.2024, 16:27
A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams before commit ea9a123 allows attackers to execute arbitrary Javascript via sending a crafted URL.
Vendor | Product | Version |
---|---|---|
tabatkins | railroad-diagram_generator | 𝑥 < 2024-01-15 |
𝑥
= Vulnerable software versions