SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-1348

w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.

MEDIUM 5.0EPSS 2.03%

Does this matter?

Lower severity and a low EPSS score (2.03%). Track it; it rarely justifies an emergency change on its own.

Description

w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.03% probability · 80th percentile
CISA KEV
Not listed
Affected
w3m/w3m
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.