CVE-2017-16008 Information

Description

i18next is a language translation framework. Because of how the interpolation is implemented making replacements from the dictionary one at a time untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next =1.10.2.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://github.com/i18next/i18next/pull/443 https://nodesecurity.io/advisories/325

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: