CVE-2021-23784
PoC —CVSS 3.1
6.1 medium
EPSS
1%p68
Published
()
Modified
Description
This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.
- Vendors
- tempura project
- Products
- tempura
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.