CVE-2018-3773
MEDIUMMetascraper < 3.9.2 - XSS
Title source: ruleDescription
There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the `metascrape` npm module <= 3.9.2.
Exploits (1)
Scores
CVSS v3
6.1
EPSS
0.0027
EPSS Percentile
50.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
metascraper_project/metascraper
< 3.9.2
npm/metascraper
0 - 5.2.0npm
Published
Jul 30, 2018
Tracked Since
Feb 18, 2026