Vulnerabilities (CVE)

Filtered by vendor Haml-coffee Project
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-32818 1 Haml-coffee Project 1 Haml-coffee 2024-11-21 3.5 LOW 7.7 HIGH
haml-coffee is a JavaScript templating solution. haml-coffee mixes pure template data with engine configuration options through the Express render API. More specifically, haml-coffee supports overriding a series of HTML helper functions through its configuration options. A vulnerable application that passes user controlled request objects to the haml-coffee template engine may introduce RCE vulnerabilities. Additionally control over the escapeHtml parameter through template configuration polluti ...

Show More