PT-2023-23731 · Unknown · Posthog-Js
CVE-2023-32325
·
Publicado
2023-05-22
·
Atualizado
2023-06-03
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PostHog-js versions prior to 1.57.2
Description
The issue concerns a potential for cross-site scripting in the PostHog-js library. Users are advised to upgrade to version 1.57.2 to resolve the issue. For users unable to upgrade, having a Content Security Policy in place can mitigate the risk.
Recommendations
For versions prior to 1.57.2, upgrade to version 1.57.2 to patch the issue.
As a temporary workaround for users unable to upgrade, ensure that their Content Security Policy is in place.
Consider using the HTML tracking snippet on PostHog Cloud, which always guarantees the latest version of the library, thus no action is required to upgrade to the patched version.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Posthog-Js