Описание
Improper Neutralization of Input in Theia console
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.
Пакеты
Наименование
@theia/console
npm
Затронутые версииВерсия исправления
< 1.8.1
1.8.1
Связанные уязвимости
CVSS3: 6.1
nvd
почти 5 лет назад
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.