prototypejs/prototype
Releases12
Frequency7 months 2 weeks
Last Release
Stars3.53K
Prototype JavaScript framework
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| = 1.7.3 | 7.5 HIGH | 5 MEDIUM | ||
An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression Denial of Service (ReDOS) through stripping crafted HTML tags. | ||||
| = 1.6.0.1 | 4.3 MEDIUM | 4 MEDIUM | ||
Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field. | ||||
| < 1.6.0.2 | — | 7.5 HIGH | ||
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors. | ||||