Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0593 | Eta is an embedded JS templating engine that works inside Node, Deno, and the browser. XSS attack - anyone using the Express API is impacted. The problem has been resolved. Users should upgrade to version 2.0.0. As a workaround, don't pass user supplied things directly to `res.render`. |
Github GHSA |
GHSA-xrh7-m5pp-39r6 | XSS Attack with Express API |
Mon, 10 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-10T21:17:25.860Z
Reserved: 2023-01-16T17:07:46.245Z
Link: CVE-2023-23630
Updated: 2024-08-02T10:35:33.606Z
Status : Modified
Published: 2023-02-01T01:15:08.937
Modified: 2024-11-21T07:46:34.330
Link: CVE-2023-23630
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA