Vulnerabilities/

Cross-site Scripting in fullpage.js

Severity:
Medium

Description

using fullpage.js you can create a anchor tag . But when put href in anchor then it does not sanitize the url which allow for a break in the context of anchor element and can add our new element.

Recommendation

Update the fullpage.js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
fullpage.js
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing