2.6
CVSSv2

CVE-2014-0046

Published: 27/02/2014 Updated: 07/11/2023
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x prior to 1.2.2, 1.3.x prior to 1.3.2, and 1.4.x prior to 1.4.0-beta.6, when used in non-block form, allows remote malicious users to inject arbitrary web script or HTML via the title attribute.

Vulnerable Product Search on Vulmon Subscribe to Product

emberjs ember.js 1.2.0

emberjs ember.js 1.4.0

emberjs ember.js 1.3.1

emberjs ember.js 1.2.1

emberjs ember.js 1.3.0