prototypejs/prototype

prototypejs/prototype

Releases12
Frequency7 months 2 weeks
Last Release
Stars3.54K
Prototype JavaScript framework

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression Denial of Service (ReDOS) through stripping crafted HTML tags.

4.3 MEDIUM4 MEDIUM

Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.