Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-53262
Summary
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static "error.html" template for errors contains placeholders that are replaced without escaping the content first. The "error.html" is the page that is rendered when everything else fails. It can contain the following placeholders: %sveltekit.status% -- the HTTP status, and %sveltekit.error.message% -- the error message. This leads to possible injection if an app explicitly creates an error with a message that contains user controlled content. Only applications where user provided input is used in the "Error" message will be vulnerable, so the vast majority of applications will not be vulnerable. This issue affects @sveltejs/kit versions prior to 2.8.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.
- LOW
- NETWORK
- LOW
- CHANGED
- REQUIRED
- LOW
- LOW
- NONE
CWE-79 - Cross Site Scripting
Cross-Site Scripting, commonly referred to as XSS, is the most dominant class of vulnerabilities. It allows an attacker to inject malicious code into a pregnable web application and victimize its users. The exploitation of such a weakness can cause severe issues such as account takeover, and sensitive data exfiltration. Because of the prevalence of XSS vulnerabilities and their high rate of exploitation, it has remained in the OWASP top 10 vulnerabilities for years.
References
Advisory Timeline
- Published