CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370) | 6.1 |
Medium |
||
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware | 6.1 |
Medium |
||
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware. | 5.4 |
Medium |