VYPR

npm package

ep_etherpad-lite

pkg:npm/ep_etherpad-lite

Vulnerabilities (1)

  • CVE-2018-6835Feb 8, 2018
    affected < 1.6.3fixed 1.6.3

    node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.