Cross-Site Scripting (XSS) Vulnerability in Nunjucks Prior to Version 3.2.4

CVE-2023-2142

Currently unrated 🤨

Key Information

Vendor
Mozilla
Status
Nunjucks
Vendor
CVE Published:
26 November 2024

Summary

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.

Affected Version(s)

Nunjucks < 3.2.4

Refferences

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

blaiddx64
.