Vulnerabilities/

Cross-Site Scripting in shave

Severity:
Medium

Description

Versions of shave prior to 2.5.3 are vulnerable to Cross-Site Scripting. The shave package overwrites HTML elements and in doing so fails to properly encode the output. If encoded HTML input is passed into shave the output will be decoded which may lead to Cross-Site Scripting.

Recommendation

Update the shave package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
shave
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing