Showing 5 vulnerabilities on this page for medialize/uri.js

Signals CISA KEV Ransomware Nuclei
medialize vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

CRHTLF can lead to invalid protocol extraction potentially leading to XSS in medialize/uri.js

CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11.

CWE-20Apr 5, 2022
CVSS6.1v3.1EPSS0.663%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

URL Confusion When Scheme Not Supplied in medialize/uri.js

URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.

CWE-115CWE-601Apr 4, 2022
CVSS6.1v3.1EPSS0.787%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Open Redirect in medialize/uri.js

Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.

CWE-601Mar 6, 2022
CVSS6.1v3.1EPSS0.719%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Authorization Bypass Through User-Controlled Key in medialize/uri.js

Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

CWE-639Feb 16, 2022
CVSS6.5v3.1EPSS1.58%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Open Redirect in medialize/URI.js

URI.js is vulnerable to URL Redirection to Untrusted Site

CWE-601Jul 16, 2021
CVSS6.1v3.1EPSS0.91%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX