Description
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://huntr.dev/bounties/228d5548-1109-49f8-8aee-91038e88371c
Patch, Third Party Advisory x_refsource_misc
https://github.com/medialize/uri.js/commit/88805fd3da03bd7a5e60947adb49d182011f1277
Scores
CVSS v3
6.1
EPSS
0.0018
EPSS Percentile
39.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-115
CWE-601
Status
published
Products (2)
npm/urijs
0 - 1.19.11npm
uri.js_project/uri.js
< 1.19.11
Published
Apr 04, 2022
Tracked Since
Feb 18, 2026