Description
The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer.
This impacts all Safari and Internet Explorer users of Prism >=v1.1.0 that use the Previewers plugin (>=v1.10.0) or the Previewer: Easing plugin (v1.1.0 to v1.9.0).
Recommendation
Update the prismjs package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.1.0, < 1.21.0
- Patched version(s): 1.21.0
References
Could your website be exposed too?
SmartScanner can check your website for Cross-Site Scripting in Prism - prismjs and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-site Scripting in Prism - CVE-2022-23647
- Cross-site Scripting in markdown-it-highlightjs - CVE-2020-7773
- Cross-site scripting in jspdf - jspdf - CVE-2020-7690
- Cross-site scripting in jspdf - CVE-2020-7691


