Description
Affected versions of i18next
allow untrusted user input to be injected into dictionary key names, resulting in a cross-site scripting vulnerability.
Recommendation
Update the i18next
package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.10.2
- Patched version(s): 1.10.3
References
Related Issues
- Command Injection Vulnerability - CVE-2021-21315
- Cloudera HUE Account Enumeration - CVE-2016-4947
- Cross-Site Scripting in exceljs - CVE-2018-16459
- Sensitive data exposure in NATS - CVE-2020-26149
- Tags:
- npm
- i18next
Anything's wrong? Let us know Last updated on September 08, 2023