CVE-2021-23383
MEDIUMhandlebars < 4.7.7 - Prototype Pollution via Template Compilation
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2021-23383. PoCs published by fazilbaig1, dn9uy3n.
AI-analyzed exploit summary This repository contains a functional exploit and scanner for CVE-2021-23383, a Prototype Pollution vulnerability in Handlebars versions before 4.7.7. The exploit sends a crafted template payload to trigger the vulnerability, while the scanner checks for vulnerable Handlebars versions.
Description
The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
Exploits (2)
This repository contains a functional exploit and scanner for CVE-2021-23383, a Prototype Pollution vulnerability in Handlebars versions before 4.7.7. The exploit sends a crafted template payload to trigger the vulnerability, while the scanner checks for vulnerable Handlebars versions.
This repository contains a Python script that scans for the presence of vulnerable versions of the Handlebars library (CVE-2021-23383) by checking script tags in a webpage. It does not exploit the vulnerability but detects it by version assessment.
References (6)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L