Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhp6-pxh8-r675

Опубликовано: 18 июн. 2020
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Angular vulnerable to Cross-site Scripting

angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping <option> elements in <select> ones changes parsing behavior, leading to possibly unsanitizing code.

Ссылки

Пакеты

Наименование

angular

npm
Затронутые версииВерсия исправления

< 1.8.0

1.8.0

EPSS

Процентиль: 42%
0.00203
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 5 лет назад

angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.

CVSS3: 5.4
redhat
больше 5 лет назад

angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.

CVSS3: 5.4
nvd
больше 5 лет назад

angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.

CVSS3: 5.4
debian
больше 5 лет назад

angular.js prior to 1.8.0 allows cross site scripting. The regex-based ...

EPSS

Процентиль: 42%
0.00203
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79