🔙 목록으로 돌아가기

CVE-2021-3377: npm ansi_up v4 - Cross-Site Scripting

Titlenpm ansi_up v4 - Cross-Site Scripting
Authorgeeknik
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of a user's browser, leading to potential data theft or unauthorized actions.
RemediationUpgrade to v5.0.0 or later.
CVSS Score6.1
EPSS Score0.46141
CVE IDCVE-2021-3377
CWE IDCWE-79
Tags cve2021 cve xss npm ansi_up_project node.js vuln

🔍 Vulnerability Description

npm package ansi_up v4 is vulnerable to cross-site scripting because ANSI escape codes can be used to create HTML hyperlinks.

🌐 HTTP Request

GET /\u001B]8;;https://interact.sh"/onmouseover="alert(1)\u0007example\u001B]8;;\u0007 HTTP/1.1
Host: www.victim.com
Connection: close

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-3377.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-3377.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A