CVE-2021-32818 affects haml-coffee, a JavaScript templating solution, by allowing remote code execution (RCE) and reflected Cross-Site Scripting (XSS) due to improper handling of user-controlled input within its configuration options. This vulnerability has a medium severity CVSS score of 5.4, indicating it can be exploited over a network with low complexity, requiring user interaction, and potentially leading to partial confidentiality and integrity impacts. There is currently no fix available for this issue, and despite its potential impact, there is no known active exploitation, public exploit code, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.14.1CPE matchmatch criteria | cpe:2.3:a:haml-coffee_project:haml-coffee:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.