CVE-2025-1467

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Feb 23, 2025
CWE ID 79

Summary

CVE-2025-1467: Versions prior to 1.17.0 of the tarteaucitronjs package contain a Cross-site Scripting (XSS) vulnerability. Attackers can exploit this issue by manipulating the getElemWidth() and getElemHeight() functions to inject malicious scripts into a victim's web browser. This vulnerability is linked to the Snyk vulnerability report SNYK-JS-TARTEAUCITRONJS-8366541. (Source: Provided information) In simpler terms: CVE-2025-1467: The tarteaucitronjs package, prior to version 1.17.0, is susceptible to XSS attacks. Hackers can exploit the getElemWidth() and getElemHeight() functions to insert malicious code into a user's web browser. This vulnerability corresponds to SNYK-JS-TARTEAUCITRONJS-8366541. (Objective summary)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share