Vulnerabilities/

Cross-Site Scripting in semantic-ui-search

Severity:
High

Description

All versions of semantic-ui-search are vulnerable to Cross-Site Scripting. Lack of output encoding on the selection dropdowns can lead to user input being executed instead of printed as text.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
semantic-ui-search
Anything's wrong? Let us know Last updated on January 09, 2023