Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0308 | backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events connecting to your RESTful API through JSON There exists a potential Cross Site Scripting vulnerability in the `Model#Escape` function of backbone 0.3.3 and earlier, if a user is able to supply input. This is due to the regex that's replacing things to miss the conversion of things such as `<` to `<`. |
Github GHSA |
GHSA-j6p2-cx3w-6jcp | Cross-Site Scripting in backbone |
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-17T04:14:50.404Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2016-10537
No data.
Status : Modified
Published: 2018-05-31T20:29:01.317
Modified: 2026-06-17T00:39:53.900
Link: CVE-2016-10537
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Github GHSA