Описание
Cross-Site Scripting in @progress/kendo-angular-editor
Kendo UI for Angular Editor Component (npm package @progress/kendo-angular-editor) before version 1.2.3 is vulnerable to Cross-Site Scripting. When the Editor content contains potentially malicious scripts in element event handlers, they get executed.
Adding the following content to the Editor value demonstrates the issue: <img src="" onerror=alert(document.domain)>.
Пакеты
Наименование
@progress/kendo-angular-editor
npm
Затронутые версииВерсия исправления
< 1.2.3
1.2.3
Дефекты
CWE-79
Дефекты
CWE-79