SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-16015

This means that if the application did not sanitize html on behalf of forms, use of forms may be vulnerable to cross site scripting

MEDIUM 6.1EPSS 0.85%

Does this matter?

Lower severity and a low EPSS score (0.85%). Track it; it rarely justifies an emergency change on its own.

Description

Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the application did not sanitize html on behalf of forms, use of forms may be vulnerable to cross site scripting

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.85% probability · 56th percentile
CISA KEV
Not listed
Weakness
CWE-80, CWE-79
Affected
forms project/forms
Source
support@hackerone.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.