prototypejs/prototype

prototypejs/prototype

Releases12
Frequency7 months 2 weeks
Last Release
Stars3.53K
Prototype JavaScript framework

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
= 1.7.37.5 HIGH5 MEDIUM

An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression Denial of Service (ReDOS) through stripping crafted HTML tags.

= 1.6.0.14.3 MEDIUM4 MEDIUM

Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.

< 1.6.0.27.5 HIGH

Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.