Fiche vulnérabilité
CVE-2025-48051 : faille moyenne lichess powertip.ts (CVSS 6.1)
Description
powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern in which text is extracted from a DOM node and interpreted as HTML.
En bref
- Sévérité
- Moyenne (CVSS 6.1)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 15 mai 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- lichess powertip.ts