CVE-2017-16010

    Dashboard / Vulnerabilities / CVE-2017-16010

    CVE-2017-16010

    Published: 29 May 2018Last Modified: 8 Jul 2026

    Summary:

    Details: i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to be escaped, but is not. This vulnerability affects i18next 2.0.0 and later.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 70d5840ffa1a4f27f94ae19b45909ecf441d73ee
    Fixed -None

    Affected versions

    v3.4.3
    v3.4.2
    v3.4.1
    v3.4.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High