Vulnerabilities/

Cross-Site Scripting in iobroker.web

Severity:
Medium

Description

Versions of iobroker.web prior to 2.4.10 are vulnerable to Cross-Site Scripting. The package fails to escape URL parameters that may be reflected in the server response. This can be used by attackers to execute arbitrary JavaScript in the victim’s browser.

Recommendation

Update the iobroker.web package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
iobroker.web
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing