CVE-2024-8373

AngularJS improper sanitization in '<source>' element

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .


We have discovered 412,908 live websites that are affected by CVE-2024-8373.

Test my site




Affected Software

Product  AngularJS
Category JavaScript Frameworks
Vulnerable Domains412,908 live websites (100.00% of AngularJS install base)
Vulnerable Versions
  • from 0 through 1.8.3
Vulnerable Versions Count125 versions ( 95.42% of all versions)


Common Weakness Enumeration

CWE-791 Incomplete Filtering of Special Elements



Details

  • Published - Sep 9, 2024
  • Updated - Nov 22, 2024

CVE-2024-8373 usage by Country

United States82,819 websites



Israel290,268 websites
Germany6,002 websites
GB4,470 websites
Brazil3,166 websites
Switzerland2,422 websites
France2,402 websites
Netherlands2,039 websites
Russia1,563 websites
Italy1,500 websites

CVE-2024-8373 usage by TLD

.com257,353 websites
.org20,430 websites
.co.uk17,661 websites
.net12,318 websites
.com.br11,034 websites
.de8,773 websites
.com.au6,364 websites
.ch5,561 websites
.fr5,353 websites
.ca5,308 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8373

Top websites that are affected by CVE-2024-8373. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.***********.com United States**
*****************.******.com United States**
**********.com United States***
**********.com United States***
*****.google United States***
*************.**********.com United States*,***
***.******.com United States*,***
*********.**********.com United States*,***
************.com United States*,***
*********.com United States*,***
See full domain list

FAQ

CVE-2024-8373 is Incomplete Filtering of Special Elements in AngularJS
A total of 412,908 websites have been identified as vulnerable to CVE-2024-8373, discovered through global website indexing conducted by WebTechSurvey.
AngularJS is susceptible to CVE-2024-8373 vulnerability.
AngularJS versions before, and including, 1.8.3 are vulnerable to CVE-2024-8373.