CVE-2017-16043

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
04/06/2018
Last modified:
09/10/2019

Description

Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:shout_project:shout:*:*:*:*:*:node.js:*:* 0.44.0 (including) 0.50.0 (excluding)