Vulnerabilities/

Cross-Site Scripting in selectize-plugin-a11y

Severity:
Medium

Description

Versions of selectize-plugin-a11y prior to 1.1.0 are vulnerable to Cross-Site Scripting. The accessibility.liveRegion.speak function does not sanitize the msg variable before rendering it as HTML. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim’s browser.

Recommendation

Update the selectize-plugin-a11y package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
selectize-plugin-a11y
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing