← volver
CVE-2016-10547

CVE-2016-10547

EPSS 1.4%CWE-79
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 1.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
31 may 2018Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape mode. In autoescape mode, all template vars should automatically be escaped. By using an array for the keys, such as `name[]=<script>alert(1)</script>`, it is possible to bypass autoescaping and inject content into the DOM.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →