Vulnerabilities/

DOM-based XSS in gmail-js

Severity:
High

Description

Affected versions of gmail-js are vulnerable to cross-site scripting in the tools.parse_response, helper.get.visible_emails_post, and helper.get.email_data_post functions, which pass user input directly into the Function constructor.

Recommendation

Update the gmail-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
gmail-js
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing