Vulnerabilities/

Cross-site Scripting in aurelia-framework

Severity:
Medium

Description

The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnerable to XSS. The sanitizer only attempts to filter SCRIPT elements, which makes it feasible for remote attackers to conduct XSS attacks via (for example) JavaScript code in an attribute of various other elements.

Recommendation

Update the aurelia-framework package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
aurelia-framework
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing