CVE-2021-23784
03.11.2021, 18:15
This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.
Vendor | Product | Version |
---|---|---|
tempura_project | tempura | 𝑥 < 0.4.0 |
𝑥
= Vulnerable software versions
References