First published: Fri Nov 17 2017(Updated: )
nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the `ejs.renderFile()` resulting in code injection
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ejs ejs | <2.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-1000188.
The severity of CVE-2017-1000188 is medium with a severity value of 6.1.
Node.js ejs versions older than 2.5.5 are affected by CVE-2017-1000188.
The vulnerability can be exploited through a cross-site scripting (XSS) attack in the `ejs.renderFile()` function, allowing for code injection.
To fix CVE-2017-1000188, update Node.js ejs to version 2.5.5 or newer.