Vulnerabilities/

Cross-Site Scripting in htmr

Severity:
High

Description

Versions of htmr prior to 0.8.7 are vulnerable to Cross-Site Scripting (XSS). The package uses innerHTML to unescape HTML entities. This may lead to DOM-based XSS through HTML-encoded XSS payloads. This may allow an attacker to execute arbitrary JavaScript in a victim’s browser.

Recommendation

Update the htmr package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
htmr
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing