CVE-2024-8372

AngularJS improper sanitization in 'srcset' attribute

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .


We have discovered 341,098 live websites that are affected by CVE-2024-8372.

Run a Free Instant Scan




Affected Software

Product  AngularJS
Category JavaScript Frameworks
Vulnerable Domains341,098 live websites (94% of AngularJS install base)
Vulnerable Versions
  • from 0 through 1.3
Vulnerable Versions Count48 versions ( 40% of all versions)


Common Weakness Enumeration

CWE-1289 Improper Validation of Unsafe Equivalence in Input



Details

  • Published - Sep 9, 2024
  • Updated - Nov 3, 2025

Credits

  • George Kalpakas (finder)

Website Distribution by Country

Number of websites using CVE-2024-8372
United States54,487 websites



Israel264,734 websites
GB3,755 websites
Germany3,257 websites
Brazil1,790 websites
Switzerland1,352 websites
France1,128 websites
Italy1,116 websites
Netherlands1,059 websites
Australia967 websites

Website Distribution by TLD

Number of websites using CVE-2024-8372
.com221,176 websites
.org17,846 websites
.co.uk17,365 websites
.net10,365 websites
.com.br7,326 websites
.de6,159 websites
.com.au5,778 websites
.ca4,669 websites
.ch3,610 websites
.fr3,375 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8372

Top websites that are affected by CVE-2024-8372. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.***********.com United States**
**********.com United States***
***.cn China*,***
******.com United States*,***
*******.org United States**,***
******************.***.com United States**,***
************.***.com Israel**,***
*******.com United States**,***
****.es Israel**,***
**************.*****************.org United States**,***
See full domain list

FAQ

CVE-2024-8372 is Improper Validation of Unsafe Equivalence in Input in AngularJS
A total of 341,098 websites have been identified as vulnerable to CVE-2024-8372, based on global website indexing conducted by WebTechSurvey.
The AngularJS is affected by the CVE-2024-8372 vulnerability.
AngularJS versions up to 1.3 are vulnerable to CVE-2024-8372.
CVE-2024-8372 is resolved in version 1.3 of AngularJS.