mustache package prior to 2.2.1 for Node.js allows remote malicious users to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mustache.js project mustache.js |