CVE-2017-16015

MEDIUM

Forms < 1.3.0 - Basic XSS

Title source: rule
STIX 2.1

Description

Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the application did not sanitize html on behalf of forms, use of forms may be vulnerable to cross site scripting

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0024
EPSS Percentile 47.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-80 CWE-79
Status published
Products (2)
forms_project/forms < 1.3.0
npm/forms 0 - 1.3.0npm
Published Jun 04, 2018
Tracked Since Feb 18, 2026