← Back

CVE-2014-6393

nvd nist
Published: Aug 9, 2017Modified: May 13, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

Affected (15)

Products: Openjsf: Express
1 product
Express
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Openjsf
Up to 3.10.5
Version 4.0.0
Version 4.1.0
Version 4.1.1
Version 4.1.2
Version 4.2.0
Version 4.3.0
Version 4.3.1
Version 4.3.2
Version 4.4.0
Version 4.4.1
Version 4.4.2
Version 4.4.3
Version 4.4.4
Version 4.4.5

References (4)

Source: cve@mitre.org
Issue TrackingThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.