Vulnerabilities/

Cross-Site Scripting in fomantic-ui

Severity:
High

Description

Versions of fomantic-ui are vulnerable to Cross-Site Scripting. Lack of output encoding on the selection dropdowns can lead to user input being executed instead of printed as text.

Recommendation

Update the fomantic-ui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
fomantic-ui
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing