Vulnerabilities/

Cross-Site Scripting in eco

Severity:
High

Description

All versions of eco are vulnerable to Cross-Site Scripting (XSS). The package’s default __escape implementation fails to escape single quotes, which may allow attackers to execute arbitrary JavaScript on the victim’s browser.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
eco
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing