Modernizr 3.x < 3.4.0 Marked Multiple Vulnerabilities

Medium Web Application Scanning Plugin ID 112381

Synopsis

Modernizr 3.x < 3.4.0 Marked Multiple Vulnerabilities

Description

According to its self-reported version number, Modernizr is 3.x prior to 3.4.0. Therefore, it may be affected by multiple vulnerabilities due to Marked component.

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Modernizr version 3.4.0 or later.

See Also

https://github.com/Modernizr/Modernizr/pull/2027

Plugin Details

Severity: Medium

ID: 112381

Type: remote

Published: 2018/11/05

Updated: 2020/07/24

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS v3.0

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Vulnerability Information

Exploit Available: false

Patch Publication Date: 2016/06/13

Vulnerability Publication Date: 2016/06/13

Reference Information

CWE: 79

WASC: Cross-Site Scripting

OWASP: 2010-A2, 2013-A3, 2013-A9, 2017-A7, 2017-A9