Description
Versions of selectize-plugin-a11y prior to 1.1.0 are vulnerable to Cross-Site Scripting. The accessibility.liveRegion.speak function does not sanitize the msg variable before rendering it as HTML. If this variable is controlled by user input it allows attackers to execute arbitrary JavaScript in a victim’s browser.
Recommendation
Update the selectize-plugin-a11y package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.1.0
- Patched version(s): 1.1.0
References
Related Issues
- Cross-site Scripting in pandao editor.md - CVE-2019-14517
- Cross-site Scripting in tableexport.jquery.plugin - CVE-2022-1291
- Cross-site Scripting in pandao - CVE-2019-14653
- Cross-Site Scripting in serialize-to-js - CVE-2019-16772
- Tags:
- npm
- selectize-plugin-a11y
Anything's wrong? Let us know Last updated on January 09, 2023