Beveiligingsadvies

CVE-2017-16008

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-06-04 19:00:00
Laatst bijgewerkt 2024-09-16 17:53:16
Toegewezen door hackerone
CVSS-score geen score
Status PUBLISHED

Beschrijving

i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next <=1.10.2.