Template Injection

Affecting jsviews package, versions <0.9.74

Do your applications use this vulnerable package? Test your applications

Overview

jsviews is Next-generation MVVM and MVP framework - built on top of JsRender templates. Bringing templates to life.

Affected versions of the package are vulnerable to Template Injection.

Remediation

Upgrade jsviews to version 0.9.74 or higher.

References

CVSS Score

6.5
medium severity
  • Attack Vector
    Network
  • Attack Complexity
    Low
  • Privileges Required
    Low
  • User Interaction
    None
  • Scope
    Unchanged
  • Confidentiality
    Low
  • Integrity
    Low
  • Availability
    Low
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Credit
Paweł Hałdrzyński
CWE
CWE-94
Snyk ID
npm:jsviews:20160320
Disclosed
19 Mar, 2016
Published
19 Jan, 2018