CVE-2025-1467
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-1467: Versions prior to 1.17.0 of the tarteaucitronjs package contain a Cross-site Scripting (XSS) vulnerability. Attackers can exploit this issue by manipulating the getElemWidth() and getElemHeight() functions to inject malicious scripts into a victim's web browser. This vulnerability is linked to the Snyk vulnerability report SNYK-JS-TARTEAUCITRONJS-8366541. (Source: Provided information) In simpler terms: CVE-2025-1467: The tarteaucitronjs package, prior to version 1.17.0, is susceptible to XSS attacks. Hackers can exploit the getElemWidth() and getElemHeight() functions to insert malicious code into a user's web browser. This vulnerability corresponds to SNYK-JS-TARTEAUCITRONJS-8366541. (Objective summary)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.