Vulnerabilities/

Improper Neutralization of Script in Attributes in @dcl/single-sign-on-client

Severity:
High

Description

Improper input validation in the init function allows arbitrary javascript to be executed using the javascript: prefix

Recommendation

Update the @dcl/single-sign-on-client package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@dcl/single-sign-on-client
Anything's wrong? Let us know Last updated on November 05, 2023