11.0.4
1 years ago
27 days ago
Known vulnerabilities in the @haxtheweb/haxcms-nodejs package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
@haxtheweb/haxcms-nodejs is a HAXcms nodejs backend Affected versions of this package are vulnerable to Command Injection through the How to fix Command Injection? Upgrade | <11.0.3 |
@haxtheweb/haxcms-nodejs is a HAXcms nodejs backend Affected versions of this package are vulnerable to Improper Restriction of Rendered UI Layers or Frames through the iframe URL parameter. An attacker can manipulate the iframe to point to a malicious site designed to capture user credentials by convincing a user to input their login details. How to fix Improper Restriction of Rendered UI Layers or Frames? Upgrade | <11.0.0 |
@haxtheweb/haxcms-nodejs is a HAXcms nodejs backend Affected versions of this package are vulnerable to Cross-site Scripting (XSS) through the How to fix Cross-site Scripting (XSS)? Upgrade | <11.0.0 |