CVE-2017-16018
MEDIUM 6.1EPSS 1.0%
Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent URL, an attacker can get script to run in some browsers.
- CVSS v3.0
- 6.1 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v3.0
- 6.1 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 0.97% chance of exploitation in the next 30 days, 59th percentile
- Published
- 2018-06-04
- Updated
- 2024-09-16
Proof-of-concept exploits (3)
- restify/node-restify/issues/1018
- advisories/GHSA-qw3g-35hc-fcrh
- ossf-cve-benchmark/CVE-2017-160180★ · 2020-11-30