CVE-2015-8861Cross-site Scripting in Project Handlebars.js

Severity
6.1MEDIUMNVD
EPSS
0.7%
top 28.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23
Latest updateOct 23

Description

The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Patches

🔴Vulnerability Details

4
GHSA
Cross-Site Scripting in handlebars2018-10-23
OSV
Cross-Site Scripting in handlebars2018-10-23
CVEList
CVE-2015-8861: The handlebars package before 42017-01-23
OSV
CVE-2015-8861: The handlebars package before 42017-01-23

📋Vendor Advisories

1
Debian
CVE-2015-8861: mustache.js - The handlebars package before 4.0.0 for Node.js allows remote attackers to condu...2015

💬Community

1
Bugzilla
CVE-2015-8862 CVE-2015-8861 mustache: handlebars: Quoteless Attributes in Templates can lead to Content Injection2015-12-15
CVE-2015-8861 — Cross-site Scripting | cvebase