Cross-site Scripting (XSS) Affecting rendr package, versions <1.1.4


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDnpm:rendr:20160725
  • published25 Jul 2016
  • disclosed25 Jul 2016
  • creditJon Merrifield

Introduced: 25 Jul 2016

CVE-2016-1000230  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade to rendr-handlerbars version 1.1.4

Overview

Rendr-handlebars is a library that allows the handlebars templating engine to be used with Rendr framework projects. The templating can occur either on the client or the server.

Versions up to 1.1.3 have a cross site scripting (XSS) issue when rendered inside a _block during client side rendering. Server side rendering is not affected and is properly escaped.

Source: Node Security Project

Details

<>

CVSS Scores

version 3.1