CVE-2017-15878: Cross-site Scripting
(updated )
Possible Cross-site scripting via the “Contact Us feature”.
References
- blog.securelayer7.net/keystonejs-open-source-penetration-testing-report/
- www.securityfocus.com/bid/101541
- github.com/keystonejs/keystone/pull/4478
- nvd.nist.gov/vuln/detail/CVE-2017-15878
- packetstormsecurity.com/files/144756/KeystoneJS-4.0.0-beta.5-Unauthenticated-Stored-Cross-Site-Scripting.html
- www.exploit-db.com/exploits/43054/
Detect and mitigate CVE-2017-15878 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →