← back
CVE-2018-16474CWE-79

CVE-2018-16474

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.8%
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
nono source reports it
In short

The tianma-static module up to version 1.0.4 has a stored XSS vulnerability that lets attackers inject and execute malicious JavaScript code, which persists and affects all users who view the compromised content.

Technical detail

A stored cross-site scripting (XSS) vulnerability in tianma-static ≤1.0.4 allows attackers to inject arbitrary JavaScript that is permanently saved and executed in the browsers of users accessing the affected content. The vulnerability requires the ability to submit data that is stored and later rendered without proper sanitization.

Summary generated and translated by AI from the official description.
A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript.
Affected products
npm · tianma-static