4.8

CVE-2017-15881

Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" field, a different vulnerability than CVE-2017-15878.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Keystonejs ≫ Keystone SwPlatform node.js Version <= 0.3.22
Keystonejs ≫ Keystone Version 4.0.0 Update - SwPlatform node.js
Keystonejs ≫ Keystone Version 4.0.0 Update beta1 SwPlatform node.js
Keystonejs ≫ Keystone Version 4.0.0 Update beta2 SwPlatform node.js
Keystonejs ≫ Keystone Version 4.0.0 Update beta3 SwPlatform node.js
Keystonejs ≫ Keystone Version 4.0.0 Update beta4 SwPlatform node.js
Keystonejs ≫ Keystone Version 4.0.0 Update beta5 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.22% 0.646
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.8 1.7 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://blog.securelayer7.net/keystonejs-open-source-penetration-testing-report/
Third Party Advisory
Issue Tracking
http://www.securityfocus.com/bid/101541
Third Party Advisory
VDB Entry
https://github.com/keystonejs/keystone/pull/4478
Patch
Third Party Advisory
Issue Tracking
https://github.com/keystonejs/keystone/issues/4437
Third Party Advisory
Issue Tracking