Lucene search

K
cvelistMitreCVELIST:CVE-2019-20920
HistorySep 30, 2020 - 12:30 p.m.

CVE-2019-20920

2020-09-3012:30:56
mitre
www.cve.org
16
handlebars
arbitrary code execution
lookup helper
templates
javascript
server
xss

AI Score

9.1

Confidence

High

EPSS

0.007

Percentile

80.3%

Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim’s browser (effectively serving as XSS).

AI Score

9.1

Confidence

High

EPSS

0.007

Percentile

80.3%