CVE-2018-1000160
Summary
| CVE | CVE-2018-1000160 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-18 19:29:00 UTC |
| Updated | 2018-05-21 16:11:00 UTC |
| Description | RisingStack protect version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in isXss() function in lib/rules/xss.js that can result in dangerous XSS strings being validated as safe. This attack appears to be exploitable via A number of XSS strings(26) detailed in the GitHub issue #16. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Risingstack |
Protect |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| XSS Vectors - Plunker |
MISC |
embed.plnkr.co |
Third Party Advisory |
| Vulnerable to XSS attacks · Issue #16 · RisingStack/protect · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| protect/xss.js at 60b0c91e86686d34e5202419ce9ae7e8dc08edcd · RisingStack/protect · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983758 Nodejs (npm) Security Update for @risingstack/protect (GHSA-vpch-rxw3-fgx8)