CVE-2024-8373

AngularJS improper sanitization in '<source>' element

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .


We have discovered 177,233 live websites that are affected by CVE-2024-8373.

Run a Free Instant Scan




Affected Software

Product  AngularJS
Category JavaScript Frameworks
Vulnerable Domains177,233 live websites (100% of AngularJS install base)
Vulnerable Versions
  • from 0 through 1.8.3
Vulnerable Versions Count119 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-791 Incomplete Filtering of Special Elements



Details

  • Published - Sep 9, 2024
  • Updated - Nov 3, 2025

Credits

  • George Kalpakas (finder)

Website Distribution by Country

Number of websites using CVE-2024-8373
United States37,000 websites



Israel117,188 websites
GB2,852 websites
Germany2,533 websites
France1,623 websites
Netherlands1,373 websites
Brazil1,325 websites
Italy1,015 websites
Spain831 websites
Russia802 websites

Website Distribution by TLD

Number of websites using CVE-2024-8373
.com102,969 websites
.co.uk10,707 websites
.org10,432 websites
.net6,903 websites
.com.br3,825 websites
.de3,172 websites
.com.au2,747 websites
.ca2,481 websites
.nl2,308 websites
.fr2,140 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8373

Top websites that are affected by CVE-2024-8373. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.***********.com United States**
*****************.******.com United States**
**********.com United States***
*********.**********.com United States*,***
************.com United States*,***
****.***********.com United States*,***
***.cn China*,***
************.******.com United States*,***
*********.org United States*,***
*********.net United States*,***
See full domain list

FAQ

CVE-2024-8373 is Incomplete Filtering of Special Elements in AngularJS
A total of 177,233 websites have been identified as vulnerable to CVE-2024-8373, based on global website indexing conducted by WebTechSurvey.
The AngularJS is affected by the CVE-2024-8373 vulnerability.
AngularJS versions up to and including 1.8.3 are vulnerable to CVE-2024-8373.