Vulnerabilities/

Cross-Site Scripting in ngx-md

Severity:
High

Description

Versions of ngx-md prior to 6.0.3 are vulnerable to Cross-Site Scripting. Links are not properly restricted to http/https and can contain JavaScript which may lead to arbitrary code execution. Markdown input such as Click Me is rendered as a Click Me link that executes JavaScript.

Recommendation

Update the ngx-md package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ngx-md
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing