CVE-2017-16015 Vulnerability Details

  /     /     /  

CVE-2017-16015 Metadata Quick Info

CVE Published: 04/06/2018 | CVE Updated: 16/09/2024 | CVE Year: 2017
Source: hackerone | Vendor: HackerOne | Product: forms node module
Status : PUBLISHED

CVE-2017-16015 Description

Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the application did not sanitize html on behalf of forms, use of forms may be vulnerable to cross site scripting

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-80
CWE Name: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) (CWE-80)
Source: HackerOne

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).