Connect
by Sencha
Source repositories
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-4691 | Med | 0.40 | 6.1 | 0.01 | Dec 27, 2019 | Sencha Labs Connect has XSS with connect.methodOverride() | ||
| CVE-2013-7371 | Med | 0.33 | 6.1 | 0.01 | Dec 11, 2019 | node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370) | ||
| CVE-2013-7370 | Med | 0.33 | 6.1 | 0.01 | Dec 11, 2019 | node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware | ||
| CVE-2018-3717 | Med | 0.28 | 5.4 | 0.01 | Jun 7, 2018 | connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware. |
- risk 0.40cvss 6.1epss 0.01
Sencha Labs Connect has XSS with connect.methodOverride()
- risk 0.33cvss 6.1epss 0.01
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)
- risk 0.33cvss 6.1epss 0.01
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
- risk 0.28cvss 5.4epss 0.01
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.