{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-02T15:37:48.541","vulnerabilities":[{"cve":{"id":"CVE-2016-10549","sourceIdentifier":"support@hackerone.com","published":"2018-05-31T20:29:01.830","lastModified":"2024-11-21T02:44:14.650","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the CORS configuration where the value of the origin header is reflected as the value for the Access-Control-Allow-Origin header. This would allow an attacker to make AJAX requests to vulnerable hosts through cross site scripting or a malicious HTML Document, effectively bypassing the Same Origin Policy. Note that this is only an issue when `allRoutes` is set to `true` and `origin` is set to `*` or left commented out in the sails CORS config file. The problem can be compounded when the cors `credentials` setting is not provided. At that point authenticated cross domain requests are possible."},{"lang":"es","value":"Sails es un framework de estilo MVC para construir aplicaciones web en tiempo real. Las versiones 0.12.7 y anteriores tienen un problema con la configuración CORS en la que el valor de la cabecera origin se refleja como el valor para la cabecera Access-Control-Allow-Origin. Esto permitiría que un atacante realice peticiones AJAX a hosts vulnerables mediante Cross-Site Scripting (XSS) o un documento HTML malicioso, omitiendo de forma efectiva la política de mismo origen. Esto solo es un problema cuando \"allRoutes\" se establece en \"true\" y \"origin\" se establece en \"*\" o se deja como comentario en el archivo de configuración CORS de Sails. El problema puede complicarse cuando la opción \"credentials\" de CORS no se proporciona. En ese punto, es posible realizar peticiones autenticadas de Cross Domain."}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:N/I:P/A:N","baseScore":2.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sailsjs:sails:*:*:*:*:*:node.js:*:*","versionEndIncluding":"0.12.7","matchCriteriaId":"7291464D-DD3E-43E0-8CDB-F0852CAC6F44"}]}]}],"references":[{"url":"http://sailsjs.org/documentation/concepts/security/cors","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"http://sailsjs.org/documentation/reference/configuration/sails-config-cors","source":"support@hackerone.com","tags":["Vendor Advisory"]},{"url":"https://nodesecurity.io/advisories/148","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"http://sailsjs.org/documentation/concepts/security/cors","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://sailsjs.org/documentation/reference/configuration/sails-config-cors","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://nodesecurity.io/advisories/148","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}