Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9prh-257w-9277

Опубликовано: 23 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-Site Scripting in handlebars

Versions of handlebars prior to 4.0.0 are affected by a cross-site scripting vulnerability when attributes in handlebar templates are not quoted.

Proof of Concept

Template: <a href={{foo}}/>

Input: { 'foo' : 'test.com onload=alert(1)'}

Rendered result: <a href=test.com onload=alert(1)/>

Recommendation

Update to version 4.0.0 or later. Alternatively, ensure that all attributes in handlebars templates are encapsulated with quotes.

Пакеты

Наименование

handlebars

npm
Затронутые версииВерсия исправления

< 4.0.0

4.0.0

EPSS

Процентиль: 71%
0.00669
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 9 лет назад

The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.

CVSS3: 6.1
nvd
около 9 лет назад

The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.

CVSS3: 6.1
debian
около 9 лет назад

The handlebars package before 4.0.0 for Node.js allows remote attacker ...

EPSS

Процентиль: 71%
0.00669
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79