Description
The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gallery-Responsive Photo and Video Gallery by Limb Cross-Site Scripting (1.3.2)
WordPress Plugin SEO Backlinks Cross-Site Request Forgery (4.0.1)
WordPress Plugin YouTube Video Inserter Cross-Site Scripting (1.2.1.0)
Atlassian Jira CVE-2019-8448 Vulnerability (CVE-2019-8448)
WordPress Plugin Solve Media CAPTCHA Cross-Site Request Forgery (1.1.0)