CVE-2022-25875

All FrameworksSvelteCWE-OtherCVE-2022-25875

CVE-2022-25875

State: PUBLISHED · Published: 2022-07-12 · Updated: 2024-09-17 · Assigner: snyk
Description
The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2022/25xxx/CVE-2022-25875.json