CVE-2024-53382
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Published Mar 3, 2025
CWE ID 94
Summary
CVE-2024-53382 is a vulnerability affecting Prism (PrismJS) up to version 1.29.0. This issue allows an attacker to conduct DOM Clobbering, leading to Cross-Site Scripting (XSS) attacks. The flaw lies in the document.currentScript lookup mechanism, which can be manipulated by maliciously injected HTML elements, bypassing the expected JavaScript code execution. This vulnerability poses a significant risk, particularly for applications or websites that rely on user-generated content or third-party libraries like PrismJS.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.