Cross-Site Scripting in bracket-template
High severity
GitHub Reviewed
Published
May 30, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
May 30, 2019
Published to the GitHub Advisory Database
May 30, 2019
Last updated
Jan 9, 2023
All versions of
bracket-template
are vulnerable to stored cross-site scripting (XSS). This is exploitable when a variable passed in via a GET parameter is used in a template.Recommendation
No fix is currently available for this vulnerability. It is our recommendation to not install or use this module at this time.
References