CVE detail
CVE-2017-1002201 — CVE-2017-1002201
Published 2019-10-15 · Modified 2026-06-17 · Vendor haml · Product haml · Source nvd
MEDIUM
severity
CVSS-derived band
0.0145
EPSS probability
exploitation probability, 30d
71.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References