Vulnerability Details CVE-2016-10543
call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 that does not validate empty parameters, which could result in invalid input bypassing the route validation rules.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.7%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2016-10543
-
cpe:2.3:a:call_project:call:2.0.1
-
cpe:2.3:a:call_project:call:2.0.2
-
cpe:2.3:a:call_project:call:3.0.0
-
cpe:2.3:a:call_project:call:3.0.1