← volver
CVE-2024-52809

Cross-site Scripting vulnerability with prototype pollution in vue-i18n

CVSS 5.3 MEDIUMEPSS 0.6%CWE-79
vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Productos afectados
intlify · vue-i18n

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →