DOM Clobbering Vulnerability in umeditor by Vendor
CVE-2024-53387

8.8HIGH

Key Information:

Vendor

Vendor

Status
Vendor
CVE Published:
3 March 2025

What is CVE-2024-53387?

A vulnerability in umeditor v1.2.3 allows attackers to exploit DOM Clobbering, enabling the execution of arbitrary code through a specially crafted HTML element. This flaw poses significant risks as it can be leveraged to manipulate the Document Object Model and potentially compromise the security of affected applications.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-53387 : DOM Clobbering Vulnerability in umeditor by Vendor