Vulnerabilities
Vulnerable Software
Golang:  >> Go  >> 1.19.8  Security Vulnerabilities
Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set "\t\n\f\r\u0020\u2028\u2029" in JavaScript contexts that also contain actions may not be properly sanitized during execution.
CVSS Score
9.8
EPSS Score
0.002
Published
2023-05-11
Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.
CVSS Score
7.3
EPSS Score
0.0
Published
2023-05-11


Contact Us

Shodan ® - All rights reserved