4.3
CVSSv2

CVE-2015-8861

Published: 23/01/2017 Updated: 22/04/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The handlebars package prior to 4.0.0 for Node.js allows remote malicious users to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

handlebars.js project handlebars.js

Vendor Advisories

The Log Correlation Engine (LCE) is potentially impacted by several vulnerabilities in OpenSSL (20160503), libpcre / PCRE, Libxml2, Handlebars, libcurl, and jQuery that were recently disclosed and fixed Note that due to the time involved in doing a full analysis of each issue, Tenable has opted to upgrade the included versions of each library as a ...

Github Repositories

Ex Machina's frontend build tool

nBob Ex Machina's second generation frontend build tool, based on Node and V8, focussing on: Ease of use Includes local build server Shows build errors directly in browser Performance Incremental builds Multi-core processing Predictability Single mode (no development vs production) Build on browser reload Conciseness Minimal project configuration Efficient proc