Vulnerability Details CVE-2024-29154
danielmiessler fabric through 1.3.0 allows installer/client/gui/static/js/index.js XSS because of innerHTML mishandling, such as in htmlToPlainText.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 28.2%
CVSS Severity
CVSS v3 Score 7.4
Products affected by CVE-2024-29154
-
cpe:2.3:a:danielmiessler:fabric:0.9.04
-
cpe:2.3:a:danielmiessler:fabric:1.0.0
-
cpe:2.3:a:danielmiessler:fabric:1.1.0
-
cpe:2.3:a:danielmiessler:fabric:1.1.1
-
cpe:2.3:a:danielmiessler:fabric:1.1.2
-
cpe:2.3:a:danielmiessler:fabric:1.1.3
-
cpe:2.3:a:danielmiessler:fabric:1.2.0
-
cpe:2.3:a:danielmiessler:fabric:1.3.0