Vulnerabilities/

Cross-Site Scripting in jqtree

Severity:
High

Description

Affected versions of jqtree are vulnerable to cross-site scripting in the drag and drop functionality for modifying tree data.

When a user attempts to drag a node to a different position in the hierarchy, script content existing within the node will be executed.

Recommendation

Update the jqtree package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jqtree
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing