CVE-2018-3717: Sencha Connect
Medium severity, CVSS 5.4. EPSS: 1.3% chance of exploitation in the next 30 days.
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
Affected products
- Sencha Connect: before 2.14.0 (fixed in 2.14.0)
Published 2018-06-07. Last modified 2026-06-17.