i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next <=1.10.2.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-0747 i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next <=1.10.2.
Github GHSA Github GHSA GHSA-f89g-whpf-6q9m Cross-Site Scripting in i18next
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-09-16T17:53:16.453Z

Reserved: 2017-10-29T00:00:00

Link: CVE-2017-16008

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-04T19:29:00.677

Modified: 2024-11-21T03:15:39.413

Link: CVE-2017-16008

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses