CVE-2023-30792: XSS
Published Apr 29, 2023
·Updated
Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources.
Affected Software
1 affected component
Facebook Lexical<0.10.0
Event History
Apr 29, 2023
CVE Published
via MITRE·02:21 AM
Data Sourced
via MITRE·02:21 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-30792?
CVE-2023-30792 is a vulnerability that allows for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources.
2
How does CVE-2023-30792 affect Lexical?
CVE-2023-30792 affects Lexical versions prior to v0.10.0.
3
How severe is CVE-2023-30792?
CVE-2023-30792 has a severity score of 6.1 (medium).
4
How can I fix CVE-2023-30792?
To fix CVE-2023-30792, update your Lexical installation to version v0.10.0 or higher.
5
Where can I find more information about CVE-2023-30792?
More information about CVE-2023-30792 can be found at the following reference: https://github.com/facebook/lexical/releases/tag/v0.10.0