Vulnerabilities/

AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes

Severity:
Medium

Description

Versions of angular prior to 1.5.0-beta.1 are vulnerable to Cross-Site Scripting. The package fails to sanitize xlink:href attributes, which may allow attackers to execute arbitrary JavaScript in a victim’s browser if the value is user-controlled.

Recommendation

Update the angular package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
angular
Anything's wrong? Let us know Last updated on January 27, 2023