Description
Versions of selectize-plugin-a11y prior to 1.1.0 are vulnerable to Cross-Site Scripting. The accessibility.liveRegion.speak function does not sanitize the msg variable before rendering it as HTML. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim’s browser.
Recommendation
Update the selectize-plugin-a11y package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.1.0
- Patched version(s): 1.1.0
References
Related Issues
- Cross-Site Scripting in dompurify - CVE-2019-16728
- Cross-Site Scripting in serialize-to-js - CVE-2019-16772
- AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes - CVE-2019-14863
- SQL Injection and Cross-site Scripting in class-validator - CVE-2019-18413
- Tags:
- npm
- selectize-plugin-a11y
Anything's wrong? Let us know Last updated on January 09, 2023