Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.8
CVE-2019-19919
- EPSS 24.75%
- Published 20.12.2019 23:15:11
- Last modified 21.11.2024 04:35:39
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through cra...
6.1
CVE-2015-8861
- EPSS 0.67%
- Published 23.01.2017 21:59:00
- Last modified 20.04.2025 01:37:25
The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.
1