Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects AngularJS versions 1.3.0-rc.4 and greater. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
We have discovered 341,098 live websites that are affected by CVE-2024-8372.
| Product | |
| Category | JavaScript Frameworks |
| Vulnerable Domains | 341,098 live websites (94% of AngularJS install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 48 versions ( 40% of all versions) |
| 54,487 websites | |
| 264,734 websites | |
| 3,755 websites | |
| 3,257 websites | |
| 1,790 websites | |
| 1,352 websites | |
| 1,128 websites | |
| 1,116 websites | |
| 1,059 websites | |
| 967 websites |
| .com | 221,176 websites |
| .org | 17,846 websites |
| .co.uk | 17,365 websites |
| .net | 10,365 websites |
| .com.br | 7,326 websites |
| .de | 6,159 websites |
| .com.au | 5,778 websites |
| .ca | 4,669 websites |
| .ch | 3,610 websites |
| .fr | 3,375 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.***********.com | ** | ||
| **********.com | *** | ||
| ***.cn | *,*** | ||
| ******.com | *,*** | ||
| *******.org | **,*** | ||
| ******************.***.com | **,*** | ||
| ************.***.com | **,*** | ||
| *******.com | **,*** | ||
| ****.es | **,*** | ||
| **************.*****************.org | **,*** |
FAQ