npm package
ep_etherpad-lite
pkg:npm/ep_etherpad-lite
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2018-6835 | — | < 1.6.3 | 1.6.3 | Feb 8, 2018 | node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions. |
- CVE-2018-6835Feb 8, 2018affected < 1.6.3fixed 1.6.3
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.