Cross-Site Scripting Vulnerability in i18next Language Framework
CVE-2017-16008

6.1MEDIUM

Key Information:

Vendor

Hackerone

Vendor
CVE Published:
4 June 2018

What is CVE-2017-16008?

A vulnerability in the i18next language translation framework allows an attacker to exploit how user input is processed for dictionary key replacements. This can lead to potential script injection in the browser, affecting users of i18next versions up to 1.10.2. Proper sanitization and validation of user input are crucial to mitigate the risks associated with this vulnerability.

Affected Version(s)

i18next node module <=1.10.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.