icon

We found results for “

WS-2014-0029

Good to know:

icon
icon

Date: July 16, 2014

Node text does not escape html in Jstree, This is a potential XSS issue.

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version jmleroux/zf-categories - no_fix;boing6000/plugin-kbnews - 1.0.0;boing6000/plugin-kbnews - no_fix;vufind/vufind - dev-pullrequest_accessib_turn-my-account-menu-into-ul;vufind/vufind - v1.23.0;vufind/vufind - v1.28.0;vufind/vufind - dev-legacy/lbs4-daia;vufind/vufind - dev-release-8.0;vufind/vufind - dev-demiankatz-patch-1;vufind/vufind - dev-VUFIND-1342;vufind/vufind - dev-accessibility-report;vufind/vufind - dev-autocomplete-troubleshooting;vufind/vufind - dev-legacy/mink-autoretry;vufind/vufind - v1.20.0;boing6000/impresspages - v4.3.0;boing6000/impresspages - v4.2.7;boing6000/impresspages - v4.6.5;boing6000/impresspages - v4.2.2;boing6000/impresspages - v4.4.1;boing6000/impresspages - v4.6.0;boing6000/impresspages - v4.5.0;boing6000/impresspages - v4.6.2;boing6000/impresspages - v4.2.4;boing6000/impresspages - v4.6.6;boing6000/impresspages - v2.0;boing6000/impresspages - v4.2.8;boing6000/impresspages - v4.2.3;boing6000/impresspages - v4.4.2;boing6000/impresspages - v4.6.1;boing6000/impresspages - v5.0.1;boing6000/impresspages - v4.5.1;boing6000/impresspages - v5.0.0;boing6000/impresspages - v4.7.0;boing6000/impresspages - v1.0.7;boing6000/impresspages - v4.2.5;boing6000/impresspages - v4.2.6;boing6000/impresspages - v4.6.4;boing6000/impresspages - v4.5.2;boing6000/impresspages - v4.2.1;boing6000/impresspages - v4.4.0;jsTree - 3.1.1;bokeh - 0.8.0;bokeh - 0.5.2;jstree - 3.0.3;impresspages/impresspages - v4.2.5;impresspages/impresspages - v4.2.1;impresspages/impresspages - v4.5.2;impresspages/impresspages - v5.0.0;impresspages/impresspages - v4.4.0;impresspages/impresspages - v4.6.2;impresspages/impresspages - v1.0.7;impresspages/impresspages - v4.5.0;impresspages/impresspages - v4.2.4;impresspages/impresspages - v4.7.0;impresspages/impresspages - v4.5.1;impresspages/impresspages - v4.3.0;impresspages/impresspages - v4.6.1;impresspages/impresspages - v4.2.3;impresspages/impresspages - v4.4.2;impresspages/impresspages - v4.10.1;impresspages/impresspages - v4.2.8;impresspages/impresspages - v4.6.6;impresspages/impresspages - v4.6.0;impresspages/impresspages - v4.2.6;impresspages/impresspages - v4.6.4;impresspages/impresspages - v4.6.5;impresspages/impresspages - v4.2.7;impresspages/impresspages - v4.2.2;impresspages/impresspages - v4.4.1;jquery.jstree - 3.0.1.8;sofia-holding/odoo-connector-bundle - 1.0.0;rabbitcms/backend - 0.5.11.14;rabbitcms/backend - 0.5.17.1;rabbitcms/backend - 0.6.8;rabbitcms/backend - dev-next;ComBoost.Mvc.Bootstrap - no_fix;fscakephp/bake-ext - v1.0.0;fscakephp/bake-ext - no_fix;crowdtruth/crowdtruth - dev-laravel;crowdtruth/crowdtruth - v2.0;ems/cmsable-distribution - no_fix;ems/cmsable-distribution - v0.1;intelliants/subrion - v4.2.0;intelliants/subrion - no_fix;intelliants/subrion - v4.0.0;glushkovds/simflex - no_fix;urbanway/construct - 5.0.7;urbanway/construct - no_fix;bariew/yii2-node-tree - no_fix;se7enxweb/eztags-ls - 2.0;mobilecart/frontendbundle - no_fix;ove/thesaurus-bundle - no_fix;growtask/simflex - no_fix;ove/procedures-bundle - no_fix;raindrop/page-bundle - no_fix;bramas/cakephp2-admin - no_fix;netTree - no_fix;glushkovds/simplex-admin - no_fix;glushkovds/simplex-admin - dev-fix/tables;ezsystems/eztags-ls - 1.4.1;se7enxweb/eztags - 2.0;org.webjars:jstree:3.0.3

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us