DOM-Based Cross-Site Scripting Vulnerability in Scratch-Svg-Renderer by LLK
CVE-2020-27428

6.1MEDIUM

Key Information:

Vendor

Mit

Vendor
CVE Published:
6 January 2022

What is CVE-2020-27428?

A vulnerability exists in Scratch-Svg-Renderer v0.2.0 that enables attackers to perform DOM-based cross-site scripting (XSS) attacks. By crafting a malicious sb3 file, attackers can execute arbitrary web scripts or HTML, potentially compromising user data and exposing vulnerabilities in the application's security architecture.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.