Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x prior to 1.2.2, 1.3.x prior to 1.3.2, and 1.4.x prior to 1.4.0-beta.6, when used in non-block form, allows remote malicious users to inject arbitrary web script or HTML via the title attribute.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
emberjs ember.js 1.2.0 |
||
emberjs ember.js 1.4.0 |
||
emberjs ember.js 1.3.1 |
||
emberjs ember.js 1.2.1 |
||
emberjs ember.js 1.3.0 |