Vulnerability Description
A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before commit ef22ad7 allows attackers to execute arbitrary Javascript via sending a crafted URL.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://gist.github.com/cd80/89527424f733b2b82de876e02d163150
- https://gist.github.com/cd80/89527424f733b2b82de876e02d163150
FAQ
What is CVE-2024-26465?
CVE-2024-26465 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before commit ef22ad7 allows attackers to execute arbitrary Javascript via sending a c...
How severe is CVE-2024-26465?
CVE-2024-26465 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-26465?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.