VYPR
Moderate severityNVD Advisory· Published Nov 14, 2023· Updated Aug 2, 2024

CVE-2023-48094

CVE-2023-48094

Description

A cross-site scripting (XSS) vulnerability in CesiumJS v1.111 allows attackers to execute arbitrary code in the context of the victim's browser via sending a crafted payload to /container_files/public_html/doc/index.html. NOTE: the vendor’s position is that Apps/Sandcastle/standalone.html is part of the CesiumGS/cesium GitHub repository, but is demo code that is not part of the CesiumJS JavaScript library product.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
cesiumnpm
<= 1.111.0

Affected products

2
  • CesiumJS/CesiumJSdescription
  • ghsa-coords
    Range: <= 1.111.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.