All the vulnerabilities related to the version 1.1.2 of the package
bracket-template vulnerable to reflected XSS
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
Cross-Site Scripting in bracket-template
All versions of bracket-template
are vulnerable to stored cross-site scripting (XSS). This is exploitable when a variable passed in via a GET parameter is used in a template.
No fix is currently available for this vulnerability. It is our recommendation to not install or use this module at this time.