Template Injection Affecting jsviews package, versions <0.9.74
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID npm:jsviews:20160320
- published 19 Jan 2018
- disclosed 19 Mar 2016
- credit Paweł Hałdrzyński
How to fix?
Upgrade jsviews
to version 0.9.74 or higher.
Overview
jsviews
is Next-generation MVVM and MVP framework - built on top of JsRender templates. Bringing templates to life.
Affected versions of the package are vulnerable to Template Injection.
References
CVSS Scores
version 3.1