Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f8rq-m28h-8hxj

Опубликовано: 03 сент. 2020
Источник: github
Github: Прошло ревью

Описание

Cross-Site Scripting in htmr

Versions of htmr prior to 0.8.7 are vulnerable to Cross-Site Scripting (XSS). The package uses innerHTML to unescape HTML entities. This may lead to DOM-based XSS through HTML-encoded XSS payloads. This may allow an attacker to execute arbitrary JavaScript in a victim's browser.

Recommendation

Upgrade to version 0.8.7 or later.

Пакеты

Наименование

htmr

npm
Затронутые версииВерсия исправления

< 0.8.7

0.8.7

Дефекты

CWE-79

Дефекты

CWE-79