Description
backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events connecting to your RESTful API through JSON There exists a potential Cross Site Scripting vulnerability in the `Model#Escape` function of backbone 0.3.3 and earlier, if a user is able to supply input. This is due to the regex that's replacing things to miss the conversion of things such as `<` to `<`.
Remediation
References
Related Vulnerabilities
WordPress Plugin SocialGrid 'default_services' Parameter Cross-Site Scripting (2.3)
Atlassian Jira Improper Authentication Vulnerability (CVE-2021-39119)
WebLogic CVE-2021-2394 Vulnerability (CVE-2021-2394)
WordPress Plugin Recart-The New GhostMonitor Unspecified Vulnerability (1.5.0)
MediaWiki Improper Access Control Vulnerability (CVE-2016-6336)