Description
The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Security Bypass (3.8.0 - 3.9.3)
WordPress Plugin WPML (WordPress Multilingual) Cross-Site Request Forgery (4.3.6)
WordPress Plugin WordPress Infinite Scroll-Ajax Load More Arbitrary File Upload (2.8.1.1)
phpMyAdmin Other Vulnerability (CVE-2005-0653)
WordPress Plugin WP Smart Image II Cross-Site Scripting (0.2)