CVE-2016-10537 describes a Cross-Site Scripting (XSS) vulnerability in the Model#Escape function of Backbone.js versions 0.3.3 and earlier, affecting JavaScript applications utilizing this framework. The vulnerability arises from an insufficient regular expression that fails to properly escape characters like '<', allowing user-supplied input to potentially inject malicious scripts. With a CVSS v3 score of 5.4 (Medium), this vulnerability requires user interaction and low privileges, with a network attack vector and low attack complexity. Successful exploitation could lead to limited confidentiality and integrity impacts, but no availability impact. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.3.3CPE matchmatch criteria | cpe:2.3:a:backbone_project:backbone:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.