ZeroHour

CVE-2021-23784

PoC
CVSS 3.1
6.1 medium
EPSS
1%p68
Published
()
Modified
Description

This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.

Vendors
tempura project
Products
tempura
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.