Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
We have discovered 412,908 live websites that are affected by CVE-2024-8373.
Product | |
Category | JavaScript Frameworks |
Vulnerable Domains | 412,908 live websites (100.00% of AngularJS install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 125 versions ( 95.42% of all versions) |
![]() | 82,819 websites |
![]() | 290,268 websites |
![]() | 6,002 websites |
![]() | 4,470 websites |
![]() | 3,166 websites |
![]() | 2,422 websites |
![]() | 2,402 websites |
![]() | 2,039 websites |
![]() | 1,563 websites |
![]() | 1,500 websites |
.com | 257,353 websites |
.org | 20,430 websites |
.co.uk | 17,661 websites |
.net | 12,318 websites |
.com.br | 11,034 websites |
.de | 8,773 websites |
.com.au | 6,364 websites |
.ch | 5,561 websites |
.fr | 5,353 websites |
.ca | 5,308 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
**********.***********.com | ![]() | ** | |
*****************.******.com | ![]() | ** | |
**********.com | ![]() | *** | |
**********.com | ![]() | *** | |
![]() | *** | ||
*************.**********.com | ![]() | *,*** | |
***.******.com | ![]() | *,*** | |
*********.**********.com | ![]() | *,*** | |
************.com | ![]() | *,*** | |
*********.com | ![]() | *,*** |
FAQ