Логотип exploitDog
bind:CVE-2025-23026
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-23026

Количество 2

Количество 2

nvd логотип

CVE-2025-23026

около 1 года назад

jte (Java Template Engine) is a secure and lightweight template engine for Java and Kotlin. In affected versions Jte HTML templates with `script` tags or script attributes that include a Javascript template string (backticks) are subject to XSS. The `javaScriptBlock` and `javaScriptAttribute` methods in the `Escape` class do not escape backticks, which are used for Javascript template strings. Dollar signs in template strings should also be escaped as well to prevent undesired interpolation. HTML templates rendered by Jte's `OwaspHtmlTemplateOutput` in versions less than or equal to `3.1.15` with `script` tags or script attributes that contain Javascript template strings (backticks) are vulnerable. Users are advised to upgrade to version 3.1.16 or later to resolve this issue. There are no known workarounds for this vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-vh22-6c6h-rm8q

около 1 года назад

jte's HTML templates containing Javascript template strings are subject to XSS

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-23026

jte (Java Template Engine) is a secure and lightweight template engine for Java and Kotlin. In affected versions Jte HTML templates with `script` tags or script attributes that include a Javascript template string (backticks) are subject to XSS. The `javaScriptBlock` and `javaScriptAttribute` methods in the `Escape` class do not escape backticks, which are used for Javascript template strings. Dollar signs in template strings should also be escaped as well to prevent undesired interpolation. HTML templates rendered by Jte's `OwaspHtmlTemplateOutput` in versions less than or equal to `3.1.15` with `script` tags or script attributes that contain Javascript template strings (backticks) are vulnerable. Users are advised to upgrade to version 3.1.16 or later to resolve this issue. There are no known workarounds for this vulnerability.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-vh22-6c6h-rm8q

jte's HTML templates containing Javascript template strings are subject to XSS

CVSS3: 6.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу