CVE-2024-42515

CRITICAL

glossarizer <= 1.5.2 - Stored Cross-Site Scripting via Glossary Entry Injection

Title source: llm
STIX 2.1

Description

Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these encoded characters into legitimate HTML, thereby possibly causing stored XSS. Attackers can append a XSS payload to a word that has a corresponding glossary entry.

Scores

CVSS v3 9.9
EPSS 0.0015
EPSS Percentile 35.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
npm/glossarizer 0npm
Published Oct 31, 2024
Tracked Since Feb 18, 2026