PT-2018-4704 · Node Angular · I18N-Node-Angular

Published

2018-05-31

·

Updated

2022-04-06

·

CVE-2016-10524

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions i18n-node-angular versions prior to 1.4.0
Description The issue concerns a REST API endpoint created for development purposes in i18n-node-angular, which was not disabled in production environments. This oversight allows a malicious user to potentially cause a Denial of Service or content injection by filling up the server. The vulnerabilities exist in versions prior to 1.4.0 and can lead to denial of service and cross-site scripting attacks.
Recommendations Update to version 1.4.0 or later. As a temporary workaround, consider disabling the REST API endpoint used for development purposes until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation.

Fix

Special Elements Injection

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10524
GHSA-97GV-3P2C-XW7J

Affected Products

I18N-Node-Angular