CVE-2024-8372

AngularJS improper sanitization in 'srcset' attribute

Improper sanitization of the value of the '[srcset]' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .


We have discovered 382,575 live websites that are affected by CVE-2024-8372.

Test my site




Affected Software

Product  AngularJS
Category JavaScript Frameworks
Vulnerable Domains382,575 live websites (92.65% of AngularJS install base)
Vulnerable Versions
  • from 0 before 1.3
Vulnerable Versions Count49 versions ( 37.40% of all versions)


Common Weakness Enumeration

CWE-1289 Improper Validation of Unsafe Equivalence in Input



Details

  • Published - Sep 9, 2024
  • Updated - Nov 22, 2024

CVE-2024-8372 usage by Country

United States64,089 websites



Israel290,187 websites
Germany4,560 websites
GB3,792 websites
Brazil2,729 websites
Switzerland2,170 websites
France1,541 websites
Italy1,091 websites
Netherlands1,079 websites
Australia1,058 websites

CVE-2024-8372 usage by TLD

.com241,271 websites
.org19,171 websites
.co.uk17,158 websites
.net11,346 websites
.com.br10,577 websites
.de8,118 websites
.com.au6,035 websites
.ch5,384 websites
.fr5,055 websites
.ca4,834 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8372

Top websites that are affected by CVE-2024-8372. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.***********.com United States**
**********.com United States***
****.ru Russia*,***
***.cn China*,***
******.com United States*,***
*******.org United States**,***
******************.***.com United States**,***
********.com United States**,***
************.***.com United States**,***
*******.com United States**,***
See full domain list

FAQ

CVE-2024-8372 is Improper Validation of Unsafe Equivalence in Input in AngularJS
A total of 382,575 websites have been identified as vulnerable to CVE-2024-8372, discovered through global website indexing conducted by WebTechSurvey.
AngularJS is susceptible to CVE-2024-8372 vulnerability.
AngularJS versions before 1.3 are vulnerable to CVE-2024-8372.
Version 1.3 of AngularJS addresses the CVE-2024-8372 security vulnerability.