Description
Versions of @ionic/core prior to 4.0.3, 4.1.3, 4.2.1 or 4.3.1 are vulnerable to Cross-Site Scripting (XSS). The package uses the unsafe innerHTML function without sanitizing input, which may allow attackers to execute arbitrary JavaScript on the victim’s browser. This issue affects the components:
<ion-alert>.message<ion-searchbar>.placeholder<ion-infinite-scroll-content>.loadingText<ion-refresher-content>.pullingText- `
.
Recommendation
Update the @ionic/core package to the latest compatible version. Followings are version details:
Affected version(s): **>= 4.3.0, < 4.3.1 >= 4.2.0, < 4.2.1 >= 4.1.0, < 4.1.3 < 4.0.3** Patched version(s): **4.3.1 4.2.1 4.1.3 4.0.3**
References
Related Issues
- Cross site scripting Vulnerability in backstage Software Catalog - @backstage/core-components - CVE-2023-25571
- vue-i18n has cross-site scripting vulnerability with prototype pollution - @intlify/core-base - CVE-2024-52809
- vue-i18n has cross-site scripting vulnerability with prototype pollution - @intlify/vue-i18n-core - CVE-2024-52809
- vue-i18n has cross-site scripting vulnerability with prototype pollution - @intlify/core - CVE-2024-52809
You might also like:
- Tags:
- npm
- @ionic/core
Anything's wrong? Let us know Last updated on January 09, 2023


