Cross-site Scripting (XSS) Affecting rendr package, versions <0.4.8-2


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDnpm:rendr:20130709
  • published22 Nov 2016
  • disclosed8 Jul 2013
  • creditSpike Brehm

Introduced: 8 Jul 2013

CVE NOT AVAILABLE CWE-79  (opens in a new tab)

How to fix?

Upgrade rendr to version 0.4.8-2 or higher.

Overview

rendr is a module that allows you to render your Backbone.js apps on the client and the server.

Affected versions of the package do not sanitize the key value in the server router and are vulnerable to Cross-site Scripting (XSS) attacks.

Details

<>

CVSS Scores

version 3.1