Description
All versions of semantic-ui-search are vulnerable to Cross-Site Scripting. Lack of output encoding on the selection dropdowns can lead to user input being executed instead of printed as text.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 0
References
Could your website be exposed too?
SmartScanner can check your website for Cross-Site Scripting in semantic-ui-search and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-site Scripting in @spscommerce/ds-react - Vulnerability
- RSSHub Cross-site Scripting vulnerability caused by internal media proxy - CVE-2024-27926
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes - CVE-2024-29203
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


