« Volver al listado

CVE-2026-5090

Estado: AplazadaMedia (6.1)—

Template::Plugin::HTML versions before 3.103 for Perl allows HTML and JavaScript to be injected.

The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For example, the variable "var" in

would not be properly escaped. An attacker could insert some limited HTML and JavaScript, for example,

Note that arbitrary HTML and JavaScript would be difficult to inject, because angle brackets, ampersands and double-quotes would still be escaped.

Detalles técnicos trazas, registros y código del informe original
    <a id='ref' title='[% var | html %]'>

    var = " ' onclick='while (true) { alert(1) }'"

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-5090",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-5090",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-20T13:45:07.748170Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "affectedData": [
        {
          "repo": "https://github.com/abw/Template2",
          "modules": [
            "Template::Plugin::HTML"
          ],
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.103",
              "versionType": "custom"
            }
          ],
          "packageURL": "pkg:cpan/Template-Toolkit",
          "packageName": "Template-Toolkit",
          "programFiles": [
            "lib/Template/Plugin/HTML.pm"
          ],
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "Template::Plugin::HTML::html_filter"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-19T22:16:39.003",
  "references": [
    {
      "url": "https://github.com/abw/Template2/issues/327",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://github.com/cpan-authors/Template2/commit/ca539f49f6ffd1c2b7d9ef4f48f6b88292418734.patch",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "https://metacpan.org/release/TODDR/Template-Toolkit-3.103/changes",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/05/19/40",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Template::Plugin::HTML versions before 3.103 for Perl allows HTML and JavaScript to be injected.\n\nThe html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected.  For example, the variable \"var\" in\n\n    <a id='ref' title='[% var | html %]'>\n\nwould not be properly escaped. An attacker could insert some limited HTML and JavaScript, for example,\n\n    var = \" ' onclick='while (true) { alert(1) }'\"\n\nNote that arbitrary HTML and JavaScript would be difficult to inject, because angle brackets, ampersands and double-quotes would still be escaped."
    },
    {
      "lang": "es",
      "value": "Las versiones de Template::Plugin::HTML hasta la 3.102 para Perl permiten la inyección de HTML y JavaScript.\n\nLa función html_filter no escapaba las comillas simples. Los atributos HTML dentro de comillas simples podrían ser objeto de inyección de código. Por ejemplo, la variable 'var' en\n\n    <a id='ref' title='[% var | html %]'>\n\nno se escaparía correctamente. Un atacante podría insertar algo de HTML y JavaScript limitado, por ejemplo,\n\n    var = \" ' onclick='while (true) { alert(1) }'\"\n\nTenga en cuenta que sería difícil inyectar HTML y JavaScript arbitrarios, porque los corchetes angulares, los ampersands y las comillas dobles seguirían siendo escapados."
    }
  ],
  "lastModified": "2026-09-19T12:16:39.640",
  "sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}