Vulnerabilities/

Template Injection in jsrender

Severity:
Medium

Description

Affected versions of jsrender are susceptible to a remote code execution vulnerability when used with server delivered client-side tempates which dynamically embed user input.

Recommendation

Update the jsrender package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jsrender
Anything's wrong? Let us know Last updated on September 07, 2023

This issue is available in SmartScanner Professional

See Pricing