Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3w8-37jv-2c58

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-Site Scripting in mustache

Versions of mustache prior to 2.2.1 are affected by a cross-site scripting vulnerability when attributes in mustache templates are not quoted.

Example

Template: <a href={{foo}}/>

Input: { 'foo' : 'test.com onload=alert(1)'}

Rendered result: <a href=test.com onload=alert(1)/>

Recommendation

Update to version 2.2.1 or later. Alternatively, ensure that all attributes in hmustache templates are encapsulated with quotes.

Пакеты

Наименование

mustache

npm
Затронутые версииВерсия исправления

< 2.2.1

2.2.1

EPSS

Процентиль: 40%
0.0018
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 9 лет назад

mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.

CVSS3: 6.1
nvd
около 9 лет назад

mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.

CVSS3: 6.1
debian
около 9 лет назад

mustache package before 2.2.1 for Node.js allows remote attackers to c ...

EPSS

Процентиль: 40%
0.0018
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79