CVE-2014-0046 Information
Feb 14, 2021
cve
Description
Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x before 1.2.2 1.3.x before 1.3.2 and 1.4.x before 1.4.0-beta.6 when used in non-block form allows remote attackers to inject arbitrary web script or HTML via the title attribute.
Reference
http://emberjs.com/blog/2014/02/07/ember-security-releases.html http://secunia.com/advisories/56965 http://www.openwall.com/lists/oss-security/2014/02/14/6 http://www.securityfocus.com/bid/65579 https://exchange.xforce.ibmcloud.com/vulnerabilities/91242 https://groups.google.com/forum/!topic/ember-security/1h6FRgr8lXQ
Share on: