Improper sanitization of the value of the '[srcset]' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
We have discovered 382,575 live websites that are affected by CVE-2024-8372.
Product | |
Category | JavaScript Frameworks |
Vulnerable Domains | 382,575 live websites (92.65% of AngularJS install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 49 versions ( 37.40% of all versions) |
![]() | 64,089 websites |
![]() | 290,187 websites |
![]() | 4,560 websites |
![]() | 3,792 websites |
![]() | 2,729 websites |
![]() | 2,170 websites |
![]() | 1,541 websites |
![]() | 1,091 websites |
![]() | 1,079 websites |
![]() | 1,058 websites |
.com | 241,271 websites |
.org | 19,171 websites |
.co.uk | 17,158 websites |
.net | 11,346 websites |
.com.br | 10,577 websites |
.de | 8,118 websites |
.com.au | 6,035 websites |
.ch | 5,384 websites |
.fr | 5,055 websites |
.ca | 4,834 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.***********.com | ![]() | ** | |
**********.com | ![]() | *** | |
****.ru | ![]() | *,*** | |
***.cn | ![]() | *,*** | |
******.com | ![]() | *,*** | |
*******.org | ![]() | **,*** | |
******************.***.com | ![]() | **,*** | |
********.com | ![]() | **,*** | |
************.***.com | ![]() | **,*** | |
*******.com | ![]() | **,*** |
FAQ