Description
mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.
Remediation
References
Related Vulnerabilities
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2019-15226)
Apache HTTP Server Insertion of Sensitive Information into Log File Vulnerability (CVE-2001-1556)
WordPress Plugin Insert Pages Multiple Vulnerabilities (3.6.1)
MySQL CVE-2023-22112 Vulnerability (CVE-2023-22112)
Internet Information Services Other Vulnerability (CVE-1999-1148)