CVE-2017-16015

Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the application did not sanitize html on behalf of forms, use of forms may be vulnerable to cross site scripting
Configurations

Configuration 1 (hide)

cpe:2.3:a:forms_project:forms:*:*:*:*:*:node.js:*:*

History

21 Nov 2024, 03:15

Type Values Removed Values Added
References () https://github.com/caolan/forms/commit/bc01e534a0ff863dedb2026a50bd03153bbc6a5d - Patch () https://github.com/caolan/forms/commit/bc01e534a0ff863dedb2026a50bd03153bbc6a5d - Patch
References () https://nodesecurity.io/advisories/158 - Third Party Advisory () https://nodesecurity.io/advisories/158 - Third Party Advisory

Information

Published : 2018-06-04 19:29

Updated : 2024-11-21 03:15


NVD link : CVE-2017-16015

Mitre link : CVE-2017-16015

CVE.ORG link : CVE-2017-16015


JSON object : View

Products Affected

forms_project

  • forms
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')